libpng releases 1.0.59, 1.2.49, 1.4.11, 1.5.10, and 1.6.0beta20 fix CVE-2011-3048

Glenn Randers-Pehrson <[email protected]> Thu, 29 Mar 2012 08:22:58 -0400
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CA+PdXcsK7Nr7URUqd_OYcZOADXtCh79MvFsX4OivG0jo-wRVTg__34790.3746100657$1333023811$gmane$org@mail.gmail.com>
libpng releases 1.0.59, 1.2.49, 1.4.11, 1.5.10, and 1.6.0beta19 which
fix CVE-2011-3048 are available at
ftp://ftp.simplesystems.org/pub/png/src (1.6.0beta19 at png-group/src)
and at
http://libpng.sf.net

Version 1.6.0beta20 [March 29, 2012]
  Changed chunk handler warnings into benign errors, incrementally load iCCP
  Added checksum-icc.c to contrib/tools
  Prevent PNG_EXPAND+PNG_SHIFT doing the shift twice.
  Recognize known sRGB ICC profiles while reading; prefer writing the
    iCCP profile over writing the sRGB chunk, controlled by the
    PNG_sRGB_PROFILE_CHECKS option.
  Revised png_set_text_2() to avoid potential memory corruption (fixes
    CVE-2011-3048).

Changes in libpng15 since the last public release (1.5.9):

  Removed two useless #ifdef directives from pngread.c and one from pngrutil.c
  Always put the CMAKE_LIBRARY in "lib" (removed special WIN32 case).
  Removed empty vstudio/pngstest directory (Clifford Yapp).
  Eliminated redundant png_push_read_tEXt|zTXt|iTXt|unknown code from
    pngpread.c and use the sequential png_handle_tEXt, etc., in pngrutil.c;
    now that png_ptr->buffer is inaccessible to applications, the special
    handling is no longer useful.
  Fixed bug with png_handle_hIST with odd chunk length (Frank Busse).
  Added PNG_SAFE_LIMITS feature to pnglibconf.dfa and code in pngconf.h
    to reset the user limits to safe ones if PNG_SAFE_LIMITS is defined.
    To enable, use "CPPFLAGS=-DPNG_SAFE_LIMITS_SUPPORTED" on the configure
    command or put "#define PNG_SAFE_LIMITS_SUPPORTED" in pnglibconf.h.
  Revised the SAFE_LIMITS feature to be the same as the feature in libpng16.
  Added information about the new limits in the manual.
  Updated Makefile.in
  Removed unused "current_text" members of png_struct and the png_free()
    of png_ptr->current_text from pngread.c
  Fixed PNG_LIBPNG_BUILD_BASE_TYPE definition.
  Fixed CMF optimization of non-IDAT compressed chunks, which was added at
    libpng-1.5.4.  It sometimes produced too small of a window.
  Reject all iCCP chunks after the first, even if the first one is invalid.
  Added palette-index checking. Issue a png_benign_error() if an invalid
    index is found.
  Revised example.c to put text strings in a temporary character array
    instead of directly assigning string constants to png_textp members.
    This avoids compiler warnings when -Wwrite-strings is enabled.
  Prevent PNG_EXPAND+PNG_SHIFT doing the shift twice.
  Revised png_set_text_2() to avoid potential memory corruption (fixes
    CVE-2011-3048).

Changes in libpng10, libpng12, libpng14 since the last public release
(1.0.58, 1.2.48, 1.4.10):

  Revised png_set_text_2() to avoid potential memory corruption (fixes
    CVE-2011-3048).
  Prevent PNG_EXPAND+PNG_SHIFT doing the shift twice.

Glenn

------------------------------------------------------------------------------
This SF email is sponsosred by:
Try Windows Azure free for 90 days Click Here 
http://p.sf.net/sfu/sfd2d-msazure