libpng-1.0.63 and 1.2.53 are available

Glenn Randers-Pehrson <[email protected]> Thu, 26 Feb 2015 16:07:24 -0500
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CA+PdXcskh2fxinGvsnh5+iHOFMkO-eJ_q=Bc8Foe_8kOqr7-mw__4370.56278246946$1424984883$gmane$org@mail.gmail.com>
--===============6825272198284453993==
Content-Type: multipart/alternative; boundary=001a11359dae7d719c0510042306

--001a11359dae7d719c0510042306
Content-Type: text/plain; charset=UTF-8

libpng-1.0.63 and 1.2.53 are available from
ftp://ftp.simplesystems.org/pub/png/src/
and from
http://libpng.sf.net

Changes since the last public release (1.0.62 and 1.2.52):

  Issue a png_error() instead of a png_warning() when width is
    potentially too large for the architecture, in case the calling
    application has overridden the default 1,000,000-column limit
    (fixes CVE-2014-9495 and CVE-2015-0973).
  Quieted some harmless warnings from Coverity-scan.
  Display user limits in the output from pngtest.
  Changed PNG_USER_CHUNK_MALLOC_MAX from unlimited to 8,000,000.
    This can only be changed at library-build time.  It only
    affects the maximum memory that can be allocated to an
    ancillary chunk; it does not limit the size of IDAT
    data, which is instead limited by PNG_USER_WIDTH_MAX.
  Rebuilt configure scripts with automake-1.15 and libtool-2.4.6

Glenn

--001a11359dae7d719c0510042306
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>libpng-1.0.63 and 1.2.53 are available from<br></div>=
<div><a href=3D"ftp://ftp.simplesystems.org/pub/png/src/">ftp://ftp.simples=
ystems.org/pub/png/src/</a><br></div><div>and from<br></div><div><a href=3D=
"http://libpng.sf.net">http://libpng.sf.net</a><br></div><div><br>Changes s=
ince the last public release (1.0.62 and 1.2.52):<br><br>=C2=A0 Issue a png=
_error() instead of a png_warning() when width is<br>=C2=A0=C2=A0=C2=A0 pot=
entially too large for the architecture, in case the calling<br>=C2=A0=C2=
=A0=C2=A0 application has overridden the default 1,000,000-column limit<br>=
=C2=A0=C2=A0=C2=A0 (fixes CVE-2014-9495 and CVE-2015-0973).<br>=C2=A0 Quiet=
ed some harmless warnings from Coverity-scan.<br>=C2=A0 Display user limits=
 in the output from pngtest.<br>=C2=A0 Changed PNG_USER_CHUNK_MALLOC_MAX fr=
om unlimited to 8,000,000.<br>=C2=A0=C2=A0=C2=A0 This can only be changed a=
t library-build time.=C2=A0 It only<br>=C2=A0=C2=A0=C2=A0 affects the maxim=
um memory that can be allocated to an<br>=C2=A0=C2=A0=C2=A0 ancillary chunk=
; it does not limit the size of IDAT<br>=C2=A0=C2=A0=C2=A0 data, which is i=
nstead limited by PNG_USER_WIDTH_MAX.<br>=C2=A0 Rebuilt configure scripts w=
ith automake-1.15 and libtool-2.4.6<br><br></div>Glenn<br><div><br><br></di=
v></div>

--001a11359dae7d719c0510042306--


--===============6825272198284453993==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the 
conversation now. http://goparallel.sourceforge.net/
--===============6825272198284453993==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
png-mng-announce mailing list
png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/png-mng-announce

--===============6825272198284453993==--