Impact
The vulnerability in Portable Puzzle Collection allows an attacker to overflow a buffer when submitting a game description field. This overflow can overwrite adjacent memory, leading to unpredictable application behavior and potentially enabling local execution of attacker-controlled code. The issue is common to all versions released before the identified commit and is identified as a classic buffer overflow flaw.
Affected Systems
Simon Tatham’s Portable Puzzle Collection, all releases prior to version 20230116.5782e29, are affected by this weakness.
Risk and Exploitability
The CVSS score of 2.9 indicates low severity, and the EPSS score of < 1% reflects an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. Attack vectors are likely local, requiring an attacker to submit a crafted game description within the application. While the vulnerability could lead to memory corruption and potentially local code execution, the overall risk remains low for most systems given the limited exploitation opportunities.
OpenCVE Enrichment