Description
An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
Published: 2026-09-14
Score: 2.9 Low
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An integer overflow flaw in Portable Puzzle Collection versions before 20230116.5782e29 allows an attacker to cause a denial of service by creating an excessive amount of save states, exhausting system resources and rendering the application unusable.

Affected Systems

The vulnerability affects Simon Tatham's Portable Puzzle Collection on all platforms where the affected version is installed. No specific operating system or architecture restrictions are noted; any user running the legacy build prior to 20230116.5782e29 is susceptible.

Risk and Exploitability

The CVSS score of 2.9 indicates low severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting low exploit likelihood in the wild. The attack can be performed by an individual who can is a local or user‑initiated scenario. For most installations the risk to critical systems is modest but still warrants update.

Generated by OpenCVE AI on September 14, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install a version of Portable Puzzle Collection newer than 20230116.5782e29 from Simon Tatham’s official repository or, if no update is available, obtain the most recent source and rebuild to apply the patch.
  • If an update cannot be applied immediately, limit the number of concurrent save states by disabling auto‑save or reducing the maximum allowed count via the application’s configuration.
  • Monitor application logs for repeated save state creation failures and, if possible, notify administrators when such patterns indicate a potential denial of service attempt.

Generated by OpenCVE AI on September 14, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Excessive Save States in Portable Puzzle Collection

Mon, 14 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T04:21:03.148Z

Reserved: 2023-01-23T00:00:00.000Z

Link: CVE-2023-24288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T05:16:56.560

Modified: 2026-09-14T05:16:56.560

Link: CVE-2023-24288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T11:30:08Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound