CVE-2023-24284 Details
Description
Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.
A buffer overflow vulnerability has been identified in Portable Puzzle Collection versions prior to 20230116.5782e29. The issue arises in the is_markable() function, where improper handling of game descriptions or save files can lead to integer overflows and subsequent buffer overflows. This vulnerability can be exploited by social engineering a user into loading a malformed file or description.
Users can upgrade to Portable Puzzle Collection version 20230122.806ae71-1 or 20230116.5782e29 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986 | [email protected] | AdvisoryIssue TrackingRemedy |
| https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=5279fd24b2f4a51e760bfde873fe1d29547220a6 | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Portable Puzzle Collection | >= 20170606.272beef-1, < 20170606.272beef-1 20220801.89391ba-1 |
CPE
Remediation
| |
| Debian | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion