FreeBSD : OpenTTD -- Denial of service using forcefully crashed aircrafts (d2073237-5b52-11e3-80f7-c86000cbc6ec)
Medium Nessus Plugin ID 71166
The remote FreeBSD host is missing a security-related update.
The OpenTTD Team reports : The problem is caused by incorrectly handling the fact that the aircraft circling the corner airport will be outside of the bounds of the map. In the 'out of fuel' crash code the height of the tile under the aircraft is determined. In this case that means a tile outside of the allocated map array, which could occasionally trigger invalid reads.