Upstream information

CVE-2012-3436 at MITRE


OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a certain sequence of steps related to "the water/coast aspect of tiles which also have railtracks on one half."

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 5
Vector AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 775023 [VERIFIED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • openttd >= 1.6.1-1.1
  • openttd-data >= 1.6.1-1.1
  • openttd-dedicated >= 1.6.1-1.1
openSUSE Tumbleweed GA openttd-1.6.1-1.1

SUSE Timeline for this CVE

CVE page created: Fri Jun 28 12:55:42 2013
CVE page last modified: Fri Oct 7 12:46:17 2022