Impact
A buffer overflow vulnerability exists in the Portable Puzzle Collection, triggered when a user executes an unusually long move. The flaw allows out-of-bounds memory writes that can corrupt adjacent data; the impact is limited to local exploitation, potentially allowing the attacker to crash the application or, if conditions permit, overwrite executable code. The weakness is classified as CWE-120, indicating improper handling of input buffer sizes.
Affected Systems
Simon Tatham:Portable Puzzle Collection, any release prior to build 20230116.5782e29 is vulnerable. Users running older versions of the from source are affected.
Risk and Exploitability
The CVSS score of 2.9 indicates low severity. The EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so it has not yet been observed in widespread attacks. Given the local nature of the vulnerability and the lack of publicly available exploitation code risk could increase if an attacker can supply extended move strings, such as through remote input or embedded data (inferred).
OpenCVE Enrichment