Impact
The Portable Puzzle Collection contains a stack‑based buffer overflow that can be triggered by the 'M' command. This flaw allows an attacker who can supply input to the command to overflow a fixed‑size buffer, potentially corrupting memory, crashing the program, or potentially executing arbitrary code if the application runs with elevated privileges (inferred). The vulnerability is classified as CWE‑120.
Affected Systems
Simon Tatham's Portable Puzzle Collection, versions prior to 20230116.5782e29. The vulnerable build is the 20230116.5782e29 release or earlier.
Risk and Exploitability
The CVSS score of 2.9 indicates a low severity vulnerability. The EPSS score is 0.00121, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves local input to the 'M' command, so an attacker would need to supply a malicious input while running the application. The risk to a system depends on the privileges of the executing user and the presence of mitigations such as stack canaries or address space layout randomization.
OpenCVE Enrichment