{"id":"CVE-2023-24291","title":"Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.","summary":"Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.","severity":"low","cvss":2.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-120"],"vendor":"Simon Tatham","product":"Portable Puzzle Collection","affected":["portable_puzzle_collection < 20230116.5782e29"],"published":"2026-09-14","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-24291","references":[{"url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986","label":"cve@mitre.org"},{"url":"https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=e5717d1ba2184eb6e38b4e2a9d29dc4704aeef30","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-24291.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-24291"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-24291"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00121,"epssPercentile":0.022,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T14:56:33.135044Z"},"ingestedAt":"2026-09-14T15:23:07.466Z","slug":"CVE-2023-24291","body":"## Overview\n\nPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-24291.json)","depth":"sunlit","depthScore":16,"depthScoreParts":{"impact":16,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}