Libpng-1.5.26, 1.4.19, 1.2.56, and 1.0.66 are available
Glenn Randers-Pehrson <[email protected]> Thu, 17 Dec 2015 10:34:07 -0500
| Newsgroups | gmane.comp.graphics.png.announce |
|---|---|
| Message-ID | <CA+PdXcuCKhy_aMKq5q6_ghsj5bbpJ318zorfZO+ZuB5j-dmqQA__35740.5645926066$1450366494$gmane$org@mail.gmail.com> |
--===============4598899383975383393==
Content-Type: multipart/alternative; boundary=001a1139bb78e4b160052719c0bd
--001a1139bb78e4b160052719c0bd
Content-Type: text/plain; charset=UTF-8
libpng-1.5.26, 1.4.19, 1.2.56, and 1.0.66 are available from
ftp://ftp.simplesystems.org/pub/png/src/
and from
http://libpng.sf.net
Changes since the last public release (1.0.55, 1.2.55, 1.4.18):
Fixed an out-of-range read in png_check_keyword() (Bug report from
Qixue Xiao, CVE-2015-8540).
Corrected copyright dates in source files.
Moved png_check_keyword() from pngwutil.c to pngset.c
Changes since the last public release (1.5.25):
Fixed an out-of-range read in png_check_keyword() (Bug report from
Qixue Xiao, CVE-2015-8540).
Corrected copyright dates in source files.
Moved png_check_keyword() from pngwutil.c to pngset.c
Added keyword checks to pngset.c (John Bowler).
Libpng-1.6.20 is not vulnerable to CVE-2015-8540 so we're not
releasing 1.6.21 at this time.
Glenn
--001a1139bb78e4b160052719c0bd
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><div><div><div><div>libpng-1.5.26, 1.4.19, 1.2.56, and 1.0=
.66 are available from<br></div><a href=3D"ftp://ftp.simplesystems.org/pub/=
png/src/">ftp://ftp.simplesystems.org/pub/png/src/</a><br></div>and from<br=
></div><a href=3D"http://libpng.sf.net">http://libpng.sf.net</a><br><br>Cha=
nges since the last public release (1.0.55, 1.2.55, 1.4.18):<br><br>=C2=A0 =
Fixed an out-of-range read in png_check_keyword() (Bug report from<br>=C2=
=A0=C2=A0=C2=A0 Qixue Xiao, CVE-2015-8540).<br>=C2=A0 Corrected copyright d=
ates in source files.<br>=C2=A0 Moved png_check_keyword() from pngwutil.c t=
o pngset.c<br><br>Changes since the last public release (1.5.25):<br>=C2=A0=
Fixed an out-of-range read in png_check_keyword() (Bug report from<br>=C2=
=A0=C2=A0=C2=A0 Qixue Xiao, CVE-2015-8540).<br>=C2=A0 Corrected copyright d=
ates in source files.<br>=C2=A0 Moved png_check_keyword() from pngwutil.c t=
o pngset.c<br>=C2=A0 Added keyword checks to pngset.c (John Bowler).<br><br=
></div><div>Libpng-1.6.20 is not vulnerable to CVE-2015-8540 so we're n=
ot<br></div><div>releasing 1.6.21 at this time.<br></div><div><br></div>Gle=
nn<br><div><br></div></div>
--001a1139bb78e4b160052719c0bd--
--===============4598899383975383393==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
------------------------------------------------------------------------------
--===============4598899383975383393==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
png-mng-announce mailing list
png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/png-mng-announce
--===============4598899383975383393==--