Impact
The Portable Puzzle Collection before build 20230116.5782e29 contains an integer overflow (CWE-190) that allows a user to create an excessive number of save states. Each additional save state consumes application memory and resources; when the limit is reached the program can freeze or crash, resulting in a denial of service.
Affected Systems
Simon Tatham’s Portable Puzzle Collection on any platform where a build older than 20230116.5782e29 is installed, including all common desktop operating systems. All installations of the legacy version are susceptible.
Risk and Exploitability
The CVSS score of 2.9 signals low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local execution or the ability to trigger the save‑state creation process, so the threat is limited to machines where the application runs under the attacker’s control. The overall risk to mission‑critical systems remains modest but warrants timely mitigation.
OpenCVE Enrichment