OpenTTD -- Denial of service (server/client) via invalid read

Affected packages
1.0.0 <= openttd < 1.0.5


VuXML ID 373e412e-f748-11df-96cd-0015f2db7bde
Discovery 2010-11-20
Entry 2010-11-23

The OpenTTD Team reports:

When a client disconnects, without sending the "quit" or "client error" message, the server has a chance of reading and writing a just freed piece of memory. The writing can only happen while the server is sending the map. Depending on what happens directly after freeing the memory there is a chance of segmentation fault, and thus a denial of service.


CVE Name CVE-2010-4168