Impact
Based on the description, it is inferred that a buffer overflow occurs in the is_markable() function of the Portable Puzzle Collection. The overflow can corrupt adjacent stack memory, potentially causing the application to crash or terminate unexpectedly. This weakness is identified as CWE-120, indicating uncontrolled overwrite of existing data. Because the flaw lacks proper bounds checking, the overflow leads to a local denial of service rather than enabling remote code execution.
Affected Systems
Simon Tatham's Portable Puzzle Collection, versions prior to the commit 20230116.5782e29 (commit 5279fd24b2f4a51e760bfde873fe1d29547220a6). Users running any older build of the collection are vulnerable unless a newer update has been applied.
Risk and Exploitability
Based on the description, it is inferred that the overall risk level is low, reflected by a CVSS score of 2.9 and an EPSS score of < 1%, indicating an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most probable attack vector is local exploitation; an attacker must supply a crafted puzzle file that triggers the overflow, leading to local denial of service. Because the flaw lies within a single function and requires local code execution, the risk of widespread compromise or data leakage is limited to the process running the game.
OpenCVE Enrichment