VYPR
Unrated severityNVD Advisory· Published Oct 9, 2012· Updated Apr 29, 2026

CVE-2012-3436

CVE-2012-3436

Description

OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a certain sequence of steps related to "the water/coast aspect of tiles which also have railtracks on one half."

Affected products

7
  • OpenTTD/Openttd7 versions
    cpe:2.3:a:openttd:openttd:0.6.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:openttd:openttd:0.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:openttd:openttd:0.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openttd:openttd:0.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openttd:openttd:0.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:openttd:openttd:0.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:openttd:openttd:0.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openttd:openttd:0.7.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.