Junglewise Threat Intelligence

CVE-2023-24284: Portable Puzzle Collection buffer overflow in is_markable()

CVE-2023-24284 · Severity: low · CVSS 2.9 · Published 2026-09-14

Technologies: Portable Puzzle Collection.

Executive brief

Portable Puzzle Collection, a collection of puzzle games, contains a buffer overflow vulnerability in the is_markable() function. An attacker can craft a malformed game description or save file that, when loaded by a user, triggers a buffer overflow. This could potentially lead to code execution or application crash, though exploitation requires social engineering a user to load the malicious file.

Technical details

The vulnerability is a buffer overflow in the is_markable() function triggered by malformed game descriptions or save files. The root cause involves insufficient bounds checking when processing game state data. An attacker-controlled game description or save file can cause the application to write beyond buffer boundaries, potentially achieving arbitrary code execution. The attack vector requires local interaction—a user must be tricked into opening a malicious file. The issue was fixed in upstream commit 5279fd24b2f4a51e760bfde873fe1d29547220a6 and patched in Debian version 20230122.806ae71-1.

Affected products

  • Portable Puzzle Collection before 20230116.5782e29

Timeline

  • 2023-01-15: disclosed: Reported to Debian as bug #1028986
  • 2023-01-22: patched: Fixed in upstream commit 5279fd24b2f4a51e and Debian version 20230122.806ae71-1

References