Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
[
{
"product": "libpano13",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "libpano13 2.9.20_rc3"
}
]
}
]
bugzilla.redhat.com/show_bug.cgi?id=1946284
lists.debian.org/debian-lts-announce/2021/04/msg00010.html
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FVJRXUOBN56ZWP6QQ3NTA6DIFZMDZAEQ/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE6YZSXNVD6WZ3AG3ENL2DIHQFF24LYX/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VYDYBKHT2MNMQCUMAVJNZW4VH6MD5BOF/
security.gentoo.org/glsa/202107-47
sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/