Executive brief
Simon Tatham's Portable Puzzle Collection is a suite of logic puzzle games. A buffer overflow vulnerability in the game loading mechanism allows an attacker to cause a crash or potentially execute arbitrary code if a user opens a malformed game description or save file, typically via social engineering.
Technical details
A buffer overflow vulnerability exists in the record length parameter handling during game file loading. The vulnerability is triggered when parsing malformed game descriptions or save files, stemming from insufficient bounds checking on the record length field. An attacker can craft a malicious game description or save file that, when loaded by the application, triggers a buffer overflow. The attack requires user interaction (opening the malicious file) and does not require network access or authentication. The vulnerability has been fixed in upstream versions and Debian package version 20230122.806ae71-1.
Affected products
- Simon Tatham Portable Puzzle Collection before 20230116.5782e29
Timeline
- 2023-01-15: disclosed: Reported to Debian as bug #1028986
- 2023-01-22: patched: Fixed in upstream version and Debian sgt-puzzles 20230122.806ae71-1