Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/ | third party advisory product |
https://bugzilla.redhat.com/show_bug.cgi?id=1946284 | issue tracking third party advisory |
https://lists.debian.org/debian-lts-announce/2021/04/msg00010.html | third party advisory mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE6YZSXNVD6WZ3AG3ENL2DIHQFF24LYX/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VYDYBKHT2MNMQCUMAVJNZW4VH6MD5BOF/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FVJRXUOBN56ZWP6QQ3NTA6DIFZMDZAEQ/ | vendor advisory |
https://security.gentoo.org/glsa/202107-47 | third party advisory vendor advisory |