Impact
A buffer overflow exists in the Portable Puzzle Collection before the 20230116.5782e29 release. The flaw allows an attacker to craft a malicious save file that, when loaded, overflows a stack buffer and crashes the application, resulting in a denial of service. The vulnerability is an example of CWE-120, a classic memory corruption flaw that compromises application availability but does not directly expose data or provide remote code execution.
Affected Systems
The affected product is Simon Tatham’s Portable Puzzle Collection, versions prior to the 20230116.5782e29 revision. Users on any platform running an unpatched version of this open‑source puzzle suite are susceptible to receiving a crafted save file from a local or network source and experiencing a forced crash.
Risk and Exploitability
The CVSS score of 2.9 indicates low severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is unlikely in the wild. The likely attack vector would involve an attacker supplying a malicious save file to a target user, either by direct file transfer, phishing, or embedding the file in a shared location. Because it requires a local user to load the file, widespread remote exploitation is improbable, but an unpatched system is vulnerable to accidental or malicious crashes that can degrade user experience or cause repeated restarts.
OpenCVE Enrichment