Executive brief
Portable Puzzle Collection is a suite of logic puzzle games. A buffer overflow vulnerability in the game description parameter could allow a local attacker with access to craft malicious game data to potentially execute arbitrary code or crash the application.
Technical details
The vulnerability is a buffer overflow triggered via the game description parameter in Portable Puzzle Collection. The affected versions are before 20230116.5782e29. A buffer overflow occurs when input exceeds allocated memory bounds, potentially allowing an attacker to overwrite adjacent memory and achieve code execution or denial of service. The vulnerability appears to require local access or the ability to influence game description data. Patch availability exists in commit a539f38efd0d821c8325846fc879a3e46d6412bf and subsequent versions after 20230116.5782e29.
Affected products
- Portable Puzzle Collection before 20230116.5782e29
Timeline
- 2026-09-14: disclosed
- 2023-01-16: patched: Fix available in commit a539f38efd0d821c8325846fc879a3e46d6412bf