Junglewise Threat Intelligence

CVE-2023-24286: Portable Puzzle Collection buffer overflow in game description

CVE-2023-24286 · Severity: low · CVSS 2.9 · Published 2026-09-14

Technologies: Portable Puzzle Collection.

Executive brief

Portable Puzzle Collection is a suite of logic puzzle games. A buffer overflow vulnerability in the game description parameter could allow a local attacker with access to craft malicious game data to potentially execute arbitrary code or crash the application.

Technical details

The vulnerability is a buffer overflow triggered via the game description parameter in Portable Puzzle Collection. The affected versions are before 20230116.5782e29. A buffer overflow occurs when input exceeds allocated memory bounds, potentially allowing an attacker to overwrite adjacent memory and achieve code execution or denial of service. The vulnerability appears to require local access or the ability to influence game description data. Patch availability exists in commit a539f38efd0d821c8325846fc879a3e46d6412bf and subsequent versions after 20230116.5782e29.

Affected products

  • Portable Puzzle Collection before 20230116.5782e29

Timeline

  • 2026-09-14: disclosed
  • 2023-01-16: patched: Fix available in commit a539f38efd0d821c8325846fc879a3e46d6412bf

References