libpng version 1.6.37
Cosmin Truta <[email protected]> Tue, 16 Apr 2019 01:11:54 -0400
| Newsgroups | gmane.comp.graphics.png.announce |
|---|---|
| Message-ID | <CAAoVtZz2S=YRDMp=ZGLcPQ4UPchsMuRois1+VzvmauxkbKe91Q__44325.4723840923$1555391550$gmane$org@mail.gmail.com> |
Dear libpng users, I am pleased to announce that libpng-1.6.37 is available for download at its usual SourceForge location: https://sourceforge.net/projects/libpng/files/libpng16/1.6.37/ This is largely a bugfix-only release. Most importantly, it contains a fix for a use-after-free vulnerability (CVE-2019-7317) affecting the simplified libpng API, and a fix for a memory leak affecting the ARM NEON implementation of the palette-to-RGB(A) expansion. For authentication purposes, here are the SHA256 checksums: libpng-1.6.37.tar.gz daeb2620d829575513e35fecc83f0d3791a620b9b93d800b763542ece9390fb4 libpng-1.6.37.tar.xz 505e70834d35383537b6491e7ae8641f1a4bed1876dbfe361201fc80868d88ca lpng1637.7z 1f1e8fc10d3575c9694a72d63c49752d2251d9683b6030850d806acc5e5e86fa lpng1637.zip 3b4b1cbd0bae6822f749d39b1ccadd6297f05e2b85a83dd2ce6ecd7d09eabdf2 For the complete list of changes, see https://sourceforge.net/p/libpng/code/ci/v1.6.37/tree/ANNOUNCE -- Sincerely, Cosmin