Description
An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
Published: 2026-09-14
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Portable Puzzle Collection before build 20230116.5782e29 contains an integer overflow (CWE-190) that allows a user to create an excessive number of save states. Each additional save state consumes application memory and resources; when the limit is reached the program can freeze or crash, resulting in a denial of service.

Affected Systems

Simon Tatham’s Portable Puzzle Collection on any platform where a build older than 20230116.5782e29 is installed, including all common desktop operating systems. All installations of the legacy version are susceptible.

Risk and Exploitability

The CVSS score of 2.9 signals low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local execution or the ability to trigger the save‑state creation process, so the threat is limited to machines where the application runs under the attacker’s control. The overall risk to mission‑critical systems remains modest but warrants timely mitigation.

Generated by OpenCVE AI on September 15, 2026 at 17:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Portable Puzzle Collection version 20230116.5782e29 or later from Simon Tatham’s official repository.
  • If an immediate upgrade is unavailable, configure the application to limit the maximum number of simultaneous save states to a safe threshold.
  • Enable logging and set alerts for repeated save‑state creation failures or excessive memory consumption, and review for potential denial‑of‑service attempts.

Generated by OpenCVE AI on September 15, 2026 at 17:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Simon Tatham
Simon Tatham portable Puzzle Collection
Vendors & Products Simon Tatham
Simon Tatham portable Puzzle Collection

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Excessive Save States in Portable Puzzle Collection

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Excessive Save States in Portable Puzzle Collection

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Excessive Save States in Portable Puzzle Collection

Mon, 14 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Simon Tatham Portable Puzzle Collection
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:11:06.787Z

Reserved: 2023-01-23T00:00:00.000Z

Link: CVE-2023-24288

cve-icon Vulnrichment

Updated: 2026-09-14T15:11:01.049Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:56.560

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-24288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound