libpng-1.2.35 and libpng-1.0.43 fix security vulnerability

Glenn Randers-Pehrson <[email protected]> Wed, 18 Feb 2009 20:26:25 -0500
Newsgroups gmane.comp.graphics.png.announce
Message-ID <e56ccc8f0902181726i200f4bf0n20d919473ec409b7__2593.9633873806$1235006919$gmane$org@mail.gmail.com>
Libpng-1.0.43 and libpng-1.2.35 are available from
ftp://ftp.simplesystems.org/pub/png/src
and from
http://libpng.sf.net

These fix a vulnerability reported by Tavis Ormandy in which
some arrays of pointers are not initialized prior to using
"malloc" to define the pointers.  If the application runs out
of memory, then libpng's cleanup process will try to free
all of the pointers in the array, some of which are not
initialized.  For more details, and a patch for older libpng
versions, see libpng-1.2.34-ADVISORY.txt that is included
in the libpng-1.2.35 distribution.

Glenn

------------------------------------------------------------------------------
Open Source Business Conference (OSBC), March 24-25, 2009, San Francisco, CA
-OSBC tackles the biggest issue in open source: Open Sourcing the Enterprise
-Strategies to boost innovation and cut costs with open source participation
-Receive a $600 discount off the registration fee with the source code: SFAD
http://p.sf.net/sfu/XcvMzF8H