Impact
An integer overflow flaw in Portable Puzzle Collection versions before 20230116.5782e29 allows an attacker to cause a denial of service by creating an excessive amount of save states, exhausting system resources and rendering the application unusable.
Affected Systems
The vulnerability affects Simon Tatham's Portable Puzzle Collection on all platforms where the affected version is installed. No specific operating system or architecture restrictions are noted; any user running the legacy build prior to 20230116.5782e29 is susceptible.
Risk and Exploitability
The CVSS score of 2.9 indicates low severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting low exploit likelihood in the wild. The attack can be performed by an individual who can is a local or user‑initiated scenario. For most installations the risk to critical systems is modest but still warrants update.
OpenCVE Enrichment