Description
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
Published: 2026-09-14
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

Based on the description, it is inferred that a buffer overflow occurs in the is_markable() function of the Portable Puzzle Collection. The overflow can corrupt adjacent stack memory, potentially causing the application to crash or terminate unexpectedly. This weakness is identified as CWE-120, indicating uncontrolled overwrite of existing data. Because the flaw lacks proper bounds checking, the overflow leads to a local denial of service rather than enabling remote code execution.

Affected Systems

Simon Tatham's Portable Puzzle Collection, versions prior to the commit 20230116.5782e29 (commit 5279fd24b2f4a51e760bfde873fe1d29547220a6). Users running any older build of the collection are vulnerable unless a newer update has been applied.

Risk and Exploitability

Based on the description, it is inferred that the overall risk level is low, reflected by a CVSS score of 2.9 and an EPSS score of < 1%, indicating an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most probable attack vector is local exploitation; an attacker must supply a crafted puzzle file that triggers the overflow, leading to local denial of service. Because the flaw lies within a single function and requires local code execution, the risk of widespread compromise or data leakage is limited to the process running the game.

Generated by OpenCVE AI on September 15, 2026 at 15:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest release of the Portable Puzzle Collection that incorporates the fix included in commit 5279fd24b2f4a51e760bfde873fe1d29547220a6.
  • If an update is not possible, source puzzle files only from trusted origins and avoid opening untrusted files.
  • Configure the application to enforce strict size limits to guard against stack overflow conditions.

Generated by OpenCVE AI on September 15, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Simon Tatham
Simon Tatham portable Puzzle Collection
Vendors & Products Simon Tatham
Simon Tatham portable Puzzle Collection

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in is_markable() of Portable Puzzle Collection

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in is_markable() of Portable Puzzle Collection

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Simon Tatham Portable Puzzle Collection
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:13:29.521Z

Reserved: 2023-01-23T00:00:00.000Z

Link: CVE-2023-24284

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:36.416Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:55.173

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-24284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:19Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')