Executive brief
Simon Tatham's Portable Puzzle Collection is a collection of classic puzzle games available across multiple platforms. A vulnerability in game file and save state parsing allows an attacker to trigger a buffer overflow or integer overflow by creating malformed save files or game descriptions, potentially causing the application to crash or execute arbitrary code. Users can be tricked into loading malicious save files through social engineering.
Technical details
The vulnerability involves multiple integer overflow and buffer overflow issues in the game loading code of Portable Puzzle Collection. Malformed game descriptions or save files can trigger integer overflows that subsequently cause buffer overflows during parsing and loading. The attack vector requires user interaction—a user must be tricked into loading a specially crafted save file or game description. The Debian package does not register media type handlers for save files, limiting the attack surface. The vulnerability was fixed in upstream version 20230122.806ae71 and patched in Debian version 20230122.806ae71-1 (released 2023-01-24).
Affected products
- Simon Tatham Portable Puzzle Collection before 20230116.5782e29
Timeline
- 2023-01-15: disclosed: Bug reported to Debian
- 2023-01-22: patched: Fixed upstream in version 20230122.806ae71
- 2026-09-14: advisory: CVE-2023-24288 published on NVD