ALT-PU-2024-17677-3
Closed vulnerabilities
Published: 2021-04-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-20307
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- https://bugzilla.redhat.com/show_bug.cgi?id=1946284
- https://bugzilla.redhat.com/show_bug.cgi?id=1946284
- [debian-lts-announce] 20210412 [SECURITY] [DLA 2624-1] libpano13 security update
- [debian-lts-announce] 20210412 [SECURITY] [DLA 2624-1] libpano13 security update
- FEDORA-2021-af806dd42d
- FEDORA-2021-af806dd42d
- FEDORA-2021-67cbea4608
- FEDORA-2021-67cbea4608
- FEDORA-2021-596fc11138
- FEDORA-2021-596fc11138
- GLSA-202107-47
- GLSA-202107-47
- https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/
- https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/