Executive brief
Portable Puzzle Collection is a suite of puzzle games. A buffer overflow vulnerability can be triggered by loading a malformed game description or save file, potentially allowing an attacker to execute arbitrary code if a user can be tricked into opening a crafted file.
Technical details
This vulnerability is a buffer overflow triggered by unusually long moves or malformed game descriptions/save files during parsing. The root cause involves inadequate bounds checking when processing game state data. The attack requires social engineering (tricking a user into opening a malicious save file or game description), as the application does not automatically handle these file types. An attacker can achieve memory corruption and potentially arbitrary code execution. The vulnerability was fixed upstream by version 20230122.806ae71 and patched in Debian versions 20230122.806ae71-1 and 20191231.79a5378-3+deb11u1.
Affected products
- Simon Tatham Portable Puzzle Collection before 20230116.5782e29
Timeline
- 2023-01-15: disclosed
- 2023-01-22: patched