libpng-1.6.8 is available

Glenn Randers-Pehrson <[email protected]> Thu, 19 Dec 2013 10:33:32 -0500
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CA+PdXctZ+YXtpVRrT5c9zx_fubfSpFFHL-acuXounDEBcO0xBw__9816.09578379921$1387467252$gmane$org@mail.gmail.com>
--===============8964129011893492734==
Content-Type: multipart/alternative; boundary=089e0153700a5cde0504ede4e266

--089e0153700a5cde0504ede4e266
Content-Type: text/plain; charset=ISO-8859-1

libpng-1.6.8 is available from
ftp://ftp.simplesystems.org/pub/png/src/libpng16
and from
http://libpng.sf.net

Changes since the last public release (1.6.7):
  Changed #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED in pngpread.c to
    #ifdef PNG_SET_UNKNOWN_CHUNKS_SUPPORTED to be consistent with
    what is in pngpriv.h.
  Moved prototype for png_handle_unknown() in pngpriv.h outside of
    the #ifdef PNG_SET_UNKNOWN_CHUNKS_SUPPORTED/#endif block.
  Added "-Wall" to CFLAGS in contrib/pngminim/*/makefile
  Conditionally compile some unused functions reported by -Wall in
    pngminim.
  Fixed 'minimal' builds. Various obviously useful minimal configurations
    don't build because of missing contrib/libtests test programs and
    overly complex dependencies in scripts/pnglibconf.dfa. This change
    adds contrib/conftest/*.dfa files that can be used in automatic build
    scripts to ensure that these configurations continue to build.
  Enabled WRITE_INVERT and WRITE_PACK in contrib/pngminim/encoder.
  Fixed pngvalid 'fail' function declaration on the Intel C Compiler.
    This reverts to the previous 'static' implementation and works round
    the 'unused static function' warning by using PNG_UNUSED().
  Removed or marked PNG_UNUSED some harmless "dead assignments" reported
    by clang scan-build.
  Changed tabs to 3 spaces in png_debug macros and changed '"%s"m'
    to '"%s" m' to improve portability among compilers.
  Changed png_free_default() to free() in pngtest.c
  Tidied up pngfix inits and fixed pngtest no-write builds.
  Handle zero-length PLTE chunk or NULL palette with png_error()
    instead of png_chunk_report(), which by default issues a warning
    rather than an error, leading to later reading from a NULL pointer
    (png_ptr->palette) in png_do_expand_palette(). This is CVE-2013-6954
    and VU#650142.

Glenn

--089e0153700a5cde0504ede4e266
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>libpng-1.6.8 is available from<br><a href=3D"ftp://ft=
p.simplesystems.org/pub/png/src/libpng16">ftp://ftp.simplesystems.org/pub/p=
ng/src/libpng16</a><br></div>and from<br><a href=3D"http://libpng.sf.net">h=
ttp://libpng.sf.net</a><br>
<div><div><br>Changes since the last public release (1.6.7):<br>=A0 Changed=
 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED in pngpread.c to<br>=A0=A0=A0 #ifde=
f PNG_SET_UNKNOWN_CHUNKS_SUPPORTED to be consistent with<br>=A0=A0=A0 what =
is in pngpriv.h.<br>
=A0 Moved prototype for png_handle_unknown() in pngpriv.h outside of<br>=A0=
=A0=A0 the #ifdef PNG_SET_UNKNOWN_CHUNKS_SUPPORTED/#endif block.<br>=A0 Add=
ed &quot;-Wall&quot; to CFLAGS in contrib/pngminim/*/makefile<br>=A0 Condit=
ionally compile some unused functions reported by -Wall in<br>
=A0=A0=A0 pngminim.<br>=A0 Fixed &#39;minimal&#39; builds. Various obviousl=
y useful minimal configurations<br>=A0=A0=A0 don&#39;t build because of mis=
sing contrib/libtests test programs and<br>=A0=A0=A0 overly complex depende=
ncies in scripts/pnglibconf.dfa. This change<br>
=A0=A0=A0 adds contrib/conftest/*.dfa files that can be used in automatic b=
uild<br>=A0=A0=A0 scripts to ensure that these configurations continue to b=
uild.<br>=A0 Enabled WRITE_INVERT and WRITE_PACK in contrib/pngminim/encode=
r.<br>=A0 Fixed pngvalid &#39;fail&#39; function declaration on the Intel C=
 Compiler.<br>
=A0=A0=A0 This reverts to the previous &#39;static&#39; implementation and =
works round<br>=A0=A0=A0 the &#39;unused static function&#39; warning by us=
ing PNG_UNUSED().<br>=A0 Removed or marked PNG_UNUSED some harmless &quot;d=
ead assignments&quot; reported<br>
=A0=A0=A0 by clang scan-build.<br>=A0 Changed tabs to 3 spaces in png_debug=
 macros and changed &#39;&quot;%s&quot;m&#39;<br>=A0=A0=A0 to &#39;&quot;%s=
&quot; m&#39; to improve portability among compilers.<br>=A0 Changed png_fr=
ee_default() to free() in pngtest.c<br>
=A0 Tidied up pngfix inits and fixed pngtest no-write builds.<br>=A0 Handle=
 zero-length PLTE chunk or NULL palette with png_error()<br>=A0=A0=A0 inste=
ad of png_chunk_report(), which by default issues a warning<br>=A0=A0=A0 ra=
ther than an error, leading to later reading from a NULL pointer<br>
=A0=A0=A0 (png_ptr-&gt;palette) in png_do_expand_palette(). This is CVE-201=
3-6954<br>=A0=A0=A0 and VU#650142.<br><br></div><div>Glenn<br></div></div><=
/div>

--089e0153700a5cde0504ede4e266--


--===============8964129011893492734==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Rapidly troubleshoot problems before they affect your business. Most IT 
organizations don't have a clear picture of how application performance 
affects their revenue. With AppDynamics, you get 100% visibility into your 
Java,.NET, & PHP application. Start your 15-day FREE TRIAL of AppDynamics Pro!
http://pubads.g.doubleclick.net/gampad/clk?id=84349831&iu=/4140/ostg.clktrk
--===============8964129011893492734==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
png-mng-announce mailing list
png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/png-mng-announce

--===============8964129011893492734==--