CVE-2012-0049
published 2019-11-07CVE-2012-0049: OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
PriorityP417medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.34%
68.6th percentile
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openttd | < openttd 1.1.5-1 (bookworm) | openttd 1.1.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openttd | openttd | < 1.1.5 | 1.1.5 |
| openttd | openttd | — | — |
| openttd | openttd | >= 0 < 1.1.5-1 | 1.1.5-1 |
| openttd | openttd | >= 0 < 1.1.5-1 | 1.1.5-1 |
| openttd | openttd | >= 0 < 1.1.5-1 | 1.1.5-1 |
| openttd | openttd | >= 0 < 1.1.5-1 | 1.1.5-1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2hx-2frv-429m: OpenTTD before 1
ghsa_unreviewed·2022-04-23
CVE-2012-0049 [MEDIUM] GHSA-x2hx-2frv-429m: OpenTTD before 1
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
OSV
CVE-2012-0049: OpenTTD before 1
osv·2019-11-07·CVSS 4.3
CVE-2012-0049 [MEDIUM] CVE-2012-0049: OpenTTD before 1
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
Debian
CVE-2012-0049: openttd - OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that preven...
vendor_debian·2012·CVSS 4.3
CVE-2012-0049 [MEDIUM] CVE-2012-0049: openttd - OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that preven...
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
Scope: local
bookworm: resolved (fixed in 1.1.5-1)
bullseye: resolved (fixed in 1.1.5-1)
forky: resolved (fixed in 1.1.5-1)
sid: resolved (fixed in 1.1.5-1)
trixie: resolved (fixed in 1.1.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0049 openttd: denial of service via slow read attack
bugzilla·2012-01-16·CVSS 4.3
CVE-2012-0049 [MEDIUM] CVE-2012-0049 openttd: denial of service via slow read attack
CVE-2012-0049 openttd: denial of service via slow read attack
A denial of service flaw was reported in OpenTTD 0.3.5 through to 1.1.4 [1],[2]. If a remote attacker were to join a server and start downloading a map file very slowly, it would prevent other users from joining the server until the download was complete. As well, the game would be paused until the download completed, preventing currently-active users from continuing the game.
This has been corrected in upstream 1.1.5 (via svn r23764 [3]).
[1] http://security.openttd.org/en/CVE-2012-0049
[2] http://bugs.openttd.org/task/4955
[3] http://vcs.openttd.org/svn/changeset/23764
Discussion:
Created openttd tracking bugs for this issue
Affects: fedora-all [bug 782181]
---
I'll push the new version later today
Bugzilla
CVE-2012-0049 openttd: denial of service via slow read attack [fedora-all]
bugzilla·2012-01-16·CVSS 4.3
CVE-2012-0049 [MEDIUM] CVE-2012-0049 openttd: denial of service via slow read attack [fedora-all]
CVE-2012-0049 openttd: denial of service via slow read attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&
http://security.openttd.org/en/CVE-2012-0049http://www.debian.org/security/2012/dsa-2524http://www.openwall.com/lists/oss-security/2012/01/13/9https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0049https://security-tracker.debian.org/tracker/CVE-2012-0049http://security.openttd.org/en/CVE-2012-0049http://www.debian.org/security/2012/dsa-2524http://www.openwall.com/lists/oss-security/2012/01/13/9https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0049https://security-tracker.debian.org/tracker/CVE-2012-0049
2019-11-07
Published