CVE-2011-3341
https://notcve.org/view.php?id=CVE-2011-3341
Multiple off-by-one errors in order_cmd.cpp in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted CMD_INSERT_ORDER command. Múltiples errores off-by-one en order_cmd.cpp en OpenTTD antes de v1.1.3, permite a atacantes remotos provocar una denegación de servicio (caída del demonio) o posiblemente ejecutar código de su elección a través de un comando CMD_INSERT_ORDER • http://bugs.openttd.org/task/4745 http://bugs.openttd.org/task/4745/getfile/7707/fixcmds.diff http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066128.html http://openwall.com/lists/oss-security/2011/09/02/4 http://openwall.com/lists/oss-security/2011/09/06/2 http://secunia.com/advisories/46075 http://security.openttd.org/en/CVE-2011-3341 http://www.debian.org/security/2012/dsa-2386 http://www.securityfocus.com/bid/49439 • CWE-189: Numeric Errors •
CVE-2011-3343
https://notcve.org/view.php?id=CVE-2011-3343
Multiple buffer overflows in OpenTTD before 1.1.3 allow local users to cause a denial of service (daemon crash) or possibly gain privileges via (1) a crafted BMP file with RLE compression or (2) crafted dimensions in a BMP file. Múltiples desbordamientos de buffer en OpenTTD antes de v1.1.3, permite a usuarios locales provocar una denegación de servicio (caída del demonio) o posiblemente ganar privilegios a través de (1) un archivo BMP modificado con compresión RLE o (2) un archivo BMP con dimensiones modificadas. • http://bugs.openttd.org/task/4746 http://bugs.openttd.org/task/4747 http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066128.html http://openwall.com/lists/oss-security/2011/09/02/4 http://openwall.com/lists/oss-security/2011/09/06/2 http://secunia.com/advisories/46075 http://security.openttd.org/en/CVE-2011-3343 http://www.debian.org/security/2012/dsa-2386 http://www.securityfocus.com/bid/49439 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •