Junglewise Threat Intelligence

CVE-2023-24283: Simon Tatham's Portable Puzzle Collection buffer overflow

CVE-2023-24283 · Severity: low · CVSS 2.9 · Published 2026-09-14

Technologies: Simon Tatham Portable Puzzle Collection. Vendors: Simon Tatham.

Executive brief

Simon Tatham's Portable Puzzle Collection is a popular suite of single-player puzzle games available across multiple platforms. A buffer overflow vulnerability in save file processing allows attackers to crash the application by providing a specially crafted save file, preventing users from accessing their puzzles and potentially disrupting gameplay.

Technical details

The vulnerability is a buffer overflow triggered during game loading when processing malformed save files or game descriptions. The root cause involves integer overflow and insufficient bounds checking in the save file parser. An attacker can exploit this by crafting a malicious save file that, when loaded by a user, causes the application to crash (denial of service). While the Debian package does not register a media type handler for save files, an attacker could socially engineer a user into opening the malicious file. Patches were released in upstream version 20230122.806ae71.

Affected products

  • Simon Tatham Portable Puzzle Collection before 20230116.5782e29

Timeline

  • 2023-01-15: disclosed
  • 2023-01-22: patched
  • 2026-09-14: advisory

References

Related threats