Lucene search

K
archlinuxArchLinuxASA-202107-55
HistoryJul 21, 2021 - 12:00 a.m.

[ASA-202107-55] libpano13: arbitrary code execution

2021-07-2100:00:00
security.archlinux.org
92
libpano13
format string
vulnerability
arbitrary code
execution
upgrade

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.011

Percentile

84.3%

Arch Linux Security Advisory ASA-202107-55

Severity: Medium
Date : 2021-07-21
CVE-ID : CVE-2021-20307
Package : libpano13
Type : arbitrary code execution
Remote : No
Link : https://security.archlinux.org/AVG-1774

Summary

The package libpano13 before version 2.9.20-1 is vulnerable to
arbitrary code execution.

Resolution

Upgrade to 2.9.20-1.

pacman -Syu “libpano13>=2.9.20-1”

The problem has been fixed upstream in version 2.9.20.

Workaround

None.

Description

A format string vulnerability in panoFileOutputNamesCreate() in
libpano13 before version 2.9.20 can lead to reading and writing of
arbitrary memory values.

Impact

An attacker could disclose memory contents, or possibly execute
arbitrary code, by specifying a crafted output file name.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1946284
https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/
https://sourceforge.net/p/panotools/libpano13/ci/f02459498cb44c0087900616a7e61563d614c05f/
https://security.archlinux.org/CVE-2021-20307

OSVersionArchitecturePackageVersionFilename
ArchLinuxanyanylibpano13< 2.9.20-1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.011

Percentile

84.3%