libpng-1.0.68, 1.2.58, 1.4.21, 1.5.29, and 1.6.32 are available

Glenn Randers-Pehrson <[email protected]> Thu, 24 Aug 2017 17:14:10 -0400
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CA+PdXctH7PtYz1Y6qQNsCqL2KJn0XeDqjKsj5i1FQLKeHDVNag__8032.56115546009$1503609318$gmane$org@mail.gmail.com>
libpng-1.0.68, 1.2.58, 1.4.21, 1.5.29, and 1.6.32 are available from
https://ftp-osl.osuosl.org/pub/libpng/src/
ftp://ftp-osl.osuosl.org/pub/libpng/src/
http://libpng.download/src/
and from
http://libpng.sf.net

Libpng-1.0.68 Changes since the last public release (1.0.67):
  Added png_check_chunk_length() function, and check all chunks except
    IDAT against the default 8MB limit; check IDAT against the maximum
    size computed from IHDR parameters.
  Check for 0 return from png_get_rowbytes() and added some (size_t) typecasts
    in contrib/pngminus/*.c to stop some Coverity issues (162705, 162706,
    and 162707).

Libpng-1.2.58 Changes since the last public release (1.2.57):
  Added png_check_chunk_length() function, and check all chunks except
    IDAT against the default 8MB limit; check IDAT against the maximum
    size computed from IHDR parameters.
  Check for 0 return from png_get_rowbytes() and added some (size_t) typecasts
    in contrib/pngminus/*.c to stop some Coverity issues (162705, 162706,
    and 162707).

Libpng-1.4.21 Changes since the last public release (1.4.20):
  Moved chunk-name and chunk-length checks into PNG_EXTERN private
    png_check_chunk_name() and png_check_chunk_length() functions
    (Suggested by Max Stepin).
  Check for 0 return from png_get_rowbytes() in contrib/pngminus/*.c to stop
    some Coverity issues (162705, 162706, and 162707).

Libpng-1.5.29 Changes since the last public release (1.5.28):
  Suppress clang warnings about implicit sign changes in png.c
  Avoid potential overflow of shift operations in png_do_expand() (Aaron Boxer).
  Added missing "$(CPPFLAGS)" to the compile line for c.pic.o in
    makefile.linux and makefile.solaris-x86 (Cosmin).
  Silence clang -Wcomma warnings (Viktor Szakats).
  Update Sourceforge URLs in documentation (https instead of http).
  Moved chunk-name and chunk-length checks into PNG_EXTERN private
    png_check_chunk_name() and png_check_chunk_length() functions
    (Suggested by Max Stepin).
  Merged pngtest.c with libpng-1.6.32.
  Check for 0 return from png_get_rowbytes() in contrib/pngminus/*.c to stop
    some Coverity issues (162705, 162706, and 162707).

Libpng-1.6.32 Changes since the last public release (1.6.31):
  Avoid possible NULL dereference in png_handle_eXIf when benign_errors
    are allowed. Avoid leaking the input buffer "eXIf_buf".
  Eliminated png_ptr->num_exif member from pngstruct.h and added num_exif
    to arguments for png_get_eXIf() and png_set_eXIf().
  Added calls to png_handle_eXIf(() in pngread.c and png_write_eXIf() in
    pngwrite.c, and made various other fixes to png_write_eXIf().
  Changed name of png_get_eXIF and png_set_eXIf() to png_get_eXIf_1() and
    png_set_eXIf_1(), respectively, to avoid breaking API compatibility
    with libpng-1.6.31.
  Updated contrib/libtests/pngunknown.c with eXIf chunk.
  Initialized btoa[] in pngstest.c
  Stop memory leak when returning from png_handle_eXIf() with an error
    (Bug report from the OSS-fuzz project).
  Replaced local eXIf_buf with info_ptr-eXIf_buf in png_handle_eXIf().
  Update libpng.3 and libpng-manual.txt about eXIf functions.
  Restored png_get_eXIf() and png_set_eXIf() to maintain API compatability.
  Removed png_get_eXIf_1() and png_set_eXIf_1().
  Check length of all chunks except IDAT against user limit to fix an
    OSS-fuzz issue.
  Check length of IDAT against maximum possible IDAT size, accounting
    for height, rowbytes, interlacing and zlib/deflate overhead.
  Restored png_get_eXIf_1() and png_set_eXIf_1(), because strlen(eXIf_buf)
    does not work (the eXIf chunk data can contain zeroes).
  Require cmake-2.8.8 in CMakeLists.txt. Revised symlink creation,
    no longer using deprecated cmake LOCATION feature (Clifford Yapp).
  Fixed five-byte error in the calculation of IDAT maximum possible size.
  Moved chunk-length check into a png_check_chunk_length() private
    function (Suggested by Max Stepin).
  Moved bad pngs from tests to contrib/libtests/crashers
  Moved testing of bad pngs into a separate tests/pngtest-badpngs script
  Added the --xfail (expected FAIL) option to pngtest.c. It writes XFAIL
    in the output but PASS for the libpng test.
  Require cmake-3.0.2 in CMakeLists.txt (Clifford Yapp).
  Fix "const" declaration info_ptr argument to png_get_eXIf_1() and the
    num_exif argument to png_get_eXIf_1() (Github Issue 171).
  Added "eXIf" to "chunks_to_ignore[]" in png_set_keep_unknown_chunks().
  Added huge_IDAT.png and empty_ancillary_chunks.png to testpngs/crashers.
  Make pngtest --strict, --relax, --xfail options imply -m (multiple).
  Removed unused chunk_name parameter from png_check_chunk_length().
  Relocated setting free_me for eXIf data, to stop an OSS-fuzz leak.
  Initialize profile_header[] in png_handle_iCCP() to fix OSS-fuzz issue.
  Initialize png_ptr->row_buf[0] to 255 in png_read_row() to fix OSS-fuzz UMR.
  Attempt to fix a UMR in png_set_text_2() to fix OSS-fuzz issue.
  Increase minimum zlib stream from 9 to 14 in png_handle_iCCP(), to account
    for the minimum 'deflate' stream, and relocate the test to a point
    after the keyword has been read.
  Check that the eXIf chunk has at least 2 bytes and begins with "II" or "MM".
  Added a set of "huge_xxxx_chunk.png" files to contrib/testpngs/crashers,
    one for each known chunk type, with length = 2GB-1.
  Check for 0 return from png_get_rowbytes() and added some (size_t) typecasts
    in contrib/pngminus/*.c to stop some Coverity issues (162705, 162706,
    and 162707).
  Renamed chunks in contrib/testpngs/crashers to avoid having files whose
    names differ only in case; this causes problems with some platforms
    (github issue #172).
  Added contrib/oss-fuzz directory which contains files used by the oss-fuzz
    project (https://github.com/google/oss-fuzz/tree/master/projects/libpng).

Glenn

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot