From 8917d9a116c8ee08984a2951e8a415f6e06afc76 Mon Sep 17 00:00:00 2001 From: Robert Clausecker Date: Mon, 20 Sep 2021 08:25:59 +0200 Subject: [PATCH] security/vuxml: Add entry for libpano13 < 2.9.20 PR: 258354 Approved by: tcberner Differential Revision: https://reviews.freebsd.org/D31980 --- security/vuxml/vuln-2021.xml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml index f6849863c0f96..14948e7a6d863 100644 --- a/security/vuxml/vuln-2021.xml +++ b/security/vuxml/vuln-2021.xml @@ -69,6 +69,32 @@ + + libpano13 -- arbitrary memory access through format string vulnerability + + + libpano13 + 2.9.20 + + + + +

libpano13 developers reports:

+
+

Fix crash and security issue caused by malformed filename prefix

+
+ +
+ + CVE-2021-20307 + https://nvd.nist.gov/vuln/detail/CVE-2021-20307 + + + 2021-05-04 + 2021-09-07 + +
+ seatd-launch -- privilege escalation with SUID