Impact
The vulnerability is a buffer overflow that occurs when the program parses the record length parameter of a puzzle file. A malicious record length value causes memory to be overwritten beyond the intended bounds, leading to memory corruption.
Affected Systems
This issue affects Simon Tatham's Portable Puzzle Collection for all versions released prior to 20230116.5782e29. Those installations are vulnerable when they process a puzzle file containing a malicious record length value. The vulnerability is specific to the software's file handling routines and does not apply to later releases that have been patched.
Risk and Exploitability
The CVSS score of 2.9 indicates a low severity. No exploit data is publicly available and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is < 1%, indicating a very low probability of exploitation. The likely attack vector is local: an attacker would need to supply a specially crafted puzzle file to the program. The impact is limited to memory corruption and potential denial of service.
OpenCVE Enrichment