CVE-2021-20307
published 2021-04-05CVE-2021-20307: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.94%
77.9th percentile
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libpano13 | < libpano13 2.9.20~rc3+dfsg-1 (bookworm) | libpano13 2.9.20~rc3+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libpano13_project | libpano13 | <= 2.9.19 | — |
| libpano13_project | libpano13 | — | — |
| libpano13_project | libpano13 | — | — |
| libpano13_project | libpano13 | >= 0 < 2.9.20~rc3+dfsg-1 | 2.9.20~rc3+dfsg-1 |
| libpano13_project | libpano13 | >= 0 < 2.9.20~rc3+dfsg-1 | 2.9.20~rc3+dfsg-1 |
| libpano13_project | libpano13 | >= 0 < 2.9.20~rc3+dfsg-1 | 2.9.20~rc3+dfsg-1 |
| libpano13_project | libpano13 | >= 0 < 2.9.20~rc3+dfsg-1 | 2.9.20~rc3+dfsg-1 |
| libpano13_project | libpano13 | >= 0 < 2.9.19+dfsg-3ubuntu0.20.04.1 | 2.9.19+dfsg-3ubuntu0.20.04.1 |
| libpano13_project | libpano13 | >= 0 < 2.9.18+dfsg-6ubuntu2+esm1 | 2.9.18+dfsg-6ubuntu2+esm1 |
| libpano13_project | libpano13 | >= 0 < 2.9.19+dfsg-2ubuntu0.1~esm1 | 2.9.19+dfsg-2ubuntu0.1~esm1 |
| libpano13_project | libpano13 | >= 0 < 2.9.19+dfsg-3ubuntu0.18.04.1~esm1 | 2.9.19+dfsg-3ubuntu0.18.04.1~esm1 |
| libpano13_project | libpano13 | >= 0 < 2.9.20~rc3+dfsg-1ubuntu0.1~esm1 | 2.9.20~rc3+dfsg-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
pano13 vulnerabilities
osv·2023-06-14·CVSS 9.8
CVE-2021-20307 [CRITICAL] pano13 vulnerabilities
pano13 vulnerabilities
It was discovered that pano13 did not properly validate the prefix provided
for PTcrop's output. An attacker could use this issue to cause pano13 to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-20307)
It was discovered that pano13 did not properly handle certain crafted TIFF
images. An attacker could use this issue to cause pano13 to crash,
resulting in a denial of service. (CVE-2021-33293)
GHSA
GHSA-jj4v-f22v-8gx6: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2
ghsa_unreviewed·2022-05-24
CVE-2021-20307 [CRITICAL] CWE-134 GHSA-jj4v-f22v-8gx6: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
OSV
CVE-2021-20307: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2
osv·2021-04-05·CVSS 9.8
CVE-2021-20307 [CRITICAL] CVE-2021-20307: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
Ubuntu
pano13 vulnerabilities
vendor_ubuntu·2023-06-14·CVSS 9.8
CVE-2021-20307 [CRITICAL] pano13 vulnerabilities
Title: pano13 vulnerabilities
Summary: pano13 could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that pano13 did not properly validate the prefix provided
for PTcrop's output. An attacker could use this issue to cause pano13 to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-20307)
It was discovered that pano13 did not properly handle certain crafted TIFF
images. An attacker could use this issue to cause pano13 to crash,
resulting in a denial of service. (CVE-2021-33293)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-20307: libpano13 - Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~r...
vendor_debian·2021·CVSS 9.8
CVE-2021-20307 [CRITICAL] CVE-2021-20307: libpano13 - Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~r...
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
Scope: local
bookworm: resolved (fixed in 2.9.20~rc3+dfsg-1)
bullseye: resolved (fixed in 2.9.20~rc3+dfsg-1)
forky: resolved (fixed in 2.9.20~rc3+dfsg-1)
sid: resolved (fixed in 2.9.20~rc3+dfsg-1)
trixie: resolved (fixed in 2.9.20~rc3+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1946284https://lists.debian.org/debian-lts-announce/2021/04/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FVJRXUOBN56ZWP6QQ3NTA6DIFZMDZAEQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE6YZSXNVD6WZ3AG3ENL2DIHQFF24LYX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VYDYBKHT2MNMQCUMAVJNZW4VH6MD5BOF/https://security.gentoo.org/glsa/202107-47https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/https://bugzilla.redhat.com/show_bug.cgi?id=1946284https://lists.debian.org/debian-lts-announce/2021/04/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FVJRXUOBN56ZWP6QQ3NTA6DIFZMDZAEQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE6YZSXNVD6WZ3AG3ENL2DIHQFF24LYX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VYDYBKHT2MNMQCUMAVJNZW4VH6MD5BOF/https://security.gentoo.org/glsa/202107-47https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/
2021-04-05
Published