Upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-5c7e48fd9c 2023-11-03 18:20:20.952150 -------------------------------------------------------------------------------- Name : libpano13 Product : Fedora 39 Version : 2.9.22 Release : 1.fc39 URL : Summary : Library for manipulating panoramic images Description : Helmut Dersch's Panorama Tools library. Provides very high quality manipulation, correction and stitching of panoramic photographs. -------------------------------------------------------------------------------- Update Information: Upstream release -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 11 2023 Bruno Postle - 2.9.22-1 - Upstream release -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-5c7e48fd9c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-90ed807e04 2023-09-20 01:30:28.946871 -------------------------------------------------------------------------------- Name : libpano13 Product : Fedora 38 Version : 2.9.22 Release : 1.fc38 URL : Summary : Library for manipulating panoramic images Description : Helmut Dersch's Panorama Tools library. Provides very high quality manipulation, correction and stitching of panoramic photographs. -------------------------------------------------------------------------------- Update Information: Upstream release -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 11 2023 Bruno Postle - 2.9.22-1 - Upstream release * Thu Jul 20 2023 Fedora Release Engineering - 2.9.21-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-90ed807e04' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Upstream release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f5a6136ac8 2023-09-20 01:05:47.011057 -------------------------------------------------------------------------------- Name : libpano13 Product : Fedora 37 Version : 2.9.22 Release : 1.fc37 URL : Summary : Library for manipulating panoramic images Description : Helmut Dersch's Panorama Tools library. Provides very high quality manipulation, correction and stitching of panoramic photographs. -------------------------------------------------------------------------------- Update Information: Upstream release -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 11 2023 Bruno Postle - 2.9.22-1 - Upstream release * Thu Jul 20 2023 Fedora Release Engineering - 2.9.21-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 2.9.21-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Tue Jan 17 2023 Florian Weimer - 2.9.21-4 - C99 compatibility fix -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f5a6136ac8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c. (CVE-2021-33293) References: . MGASA-2022-0115 - Updated libpano13 packages fix security vulnerability Publication date: 24 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0115.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-33293 Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c. (CVE-2021-33293) References: - https://bugs.mageia.org/show_bug.cgi?id=30192 - https://lists.debian.org/debian-lts-announce/2022/03/msg00029.html - https://www.cve.org/CVERecord?id=CVE-2021-33293 SRPMS: - 8/core/libpano13-2.9.20-1.1.mga8 - 8/tainted/libpano13-2.9.20-1.1.mga8.tainted . Enhanced libpano13 updates tackle a boundary reading vulnerability in Mageia 8, reinforcing security protocols.. Mageia Security Updates, libpano13 Out-of-Bounds, Critical Security Issue. . Severity: Critical. LinuxSecurity.com Team
It was discovered that Panorama Tools, a toolkit to generate, edit and transform many kinds of panoramic images, contained an out-of-bounds read vulnerability which could lead to a denial of service (application crash) when a malformed image file is processed. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2957-1
The package libpano13 before version 2.9.20-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202107-55 ========================================= Severity: Medium Date : 2021-07-21 CVE-ID : CVE-2021-20307 Package : libpano13 Type : arbitrary code execution Remote : No Link : https://security.archlinux.org/AVG-1774 Summary ====== The package libpano13 before version 2.9.20-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 2.9.20-1. # pacman -Syu "libpano13> =2.9.20-1" The problem has been fixed upstream in version 2.9.20. Workaround ========= None. Description ========== A format string vulnerability in panoFileOutputNamesCreate() in libpano13 before version 2.9.20 can lead to reading and writing of arbitrary memory values. Impact ===== An attacker could disclose memory contents, or possibly execute arbitrary code, by specifying a crafted output file name. References ========= https://bugzilla.redhat.com/show_bug.cgi?id=1946284 https://sourceforge.net/projects/panotools/files/libpano13/libpano13-2.9.20/ https://security.archlinux.org/CVE-2021-20307 . The OpenSUSE Security Advisory OBS-202112-34 highlights a significant vulnerability in curl, which could result in information disclosure.. Arch Linux, libpano13, security patch, code execution flaw, resource management. . Severity: Medium. LinuxSecurity.com Team
A format string vulnerability has been found in libpano13, potentially resulting in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-47 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libpano13: Format string vulnerability Date: July 20, 2021 Bugs: #780486 ID: 202107-47 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A format string vulnerability has been found in libpano13, potentially resulting in arbitrary code execution. Background ========= libpano13 is Helmut Dersch's panorama toolbox library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libpano13 < 2.9.20 > = 2.9.20 Description ========== A format string issue exists within panoFileOutputNamesCreate() where unvalidated input is passed directly into the formatter. Impact ===== A remote attacker could entice a user to open a specially crafted file using libpano13, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All libpano13 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libpano13-2.9.20" References ========= [ 1 ] CVE-2021-20307 https://nvd.nist.gov/vuln/detail/CVE-2021-20307 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-47 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20.rc2 and earlier can lead to read and write arbitrary memory values (CVE-2021-20307). References: - https://bugs.mageia.org/show_bug.cgi?id=28997 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.