CVE-2006-3913, http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3913 : Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) negative chunk_length or a (2) large chunk->offset value in a PACKET_PLAYER_ATTRIBUTE_CHUNK packet in the generic_handle_player_attribute_chunk function in common/packets.c, and (3) a large packet->length value in the handle_unit_orders function in server/unithand.c. All FE-[345] and devel are probably affected.
Thanks for the bug report. Packages should be available after the next signing/push.
The CVE description of the vulnerability mentions three bugs, but the patch applied in latest freeciv package revisions appears to address only two of them. Maybe this is the missing piece? http://svn.gna.org/viewcvs/freeciv?rev=12146&view=rev
Yeah, that should be added to my patch. The report stated this was corrected on July 16th, but the changes you referenced weren't applied to svn until July 24th.
Seems to be fixed now, thanks.