Junglewise Threat Intelligence

CVE-2023-24285: Simon Tatham Portable Puzzle Collection buffer overflow in game loading

CVE-2023-24285 · Severity: low · CVSS 2.9 · Published 2026-09-14

Technologies: Simon Tatham Portable Puzzle Collection. Vendors: Simon Tatham.

Executive brief

Portable Puzzle Collection is a suite of puzzle games. A buffer overflow vulnerability can be triggered by loading a malformed game description or save file, potentially allowing an attacker to execute arbitrary code if a user can be tricked into opening a crafted file.

Technical details

This vulnerability is a buffer overflow triggered by unusually long moves or malformed game descriptions/save files during parsing. The root cause involves inadequate bounds checking when processing game state data. The attack requires social engineering (tricking a user into opening a malicious save file or game description), as the application does not automatically handle these file types. An attacker can achieve memory corruption and potentially arbitrary code execution. The vulnerability was fixed upstream by version 20230122.806ae71 and patched in Debian versions 20230122.806ae71-1 and 20191231.79a5378-3+deb11u1.

Affected products

  • Simon Tatham Portable Puzzle Collection before 20230116.5782e29

Timeline

  • 2023-01-15: disclosed
  • 2023-01-22: patched

References

Related threats