Libpng-1.5.26, 1.4.19, 1.2.56, and 1.0.66 are available

Glenn Randers-Pehrson <[email protected]> Thu, 17 Dec 2015 10:34:07 -0500
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CA+PdXcuCKhy_aMKq5q6_ghsj5bbpJ318zorfZO+ZuB5j-dmqQA__35740.5645926066$1450366494$gmane$org@mail.gmail.com>
--===============4598899383975383393==
Content-Type: multipart/alternative; boundary=001a1139bb78e4b160052719c0bd

--001a1139bb78e4b160052719c0bd
Content-Type: text/plain; charset=UTF-8

libpng-1.5.26, 1.4.19, 1.2.56, and 1.0.66 are available from
ftp://ftp.simplesystems.org/pub/png/src/
and from
http://libpng.sf.net

Changes since the last public release (1.0.55, 1.2.55, 1.4.18):

  Fixed an out-of-range read in png_check_keyword() (Bug report from
    Qixue Xiao, CVE-2015-8540).
  Corrected copyright dates in source files.
  Moved png_check_keyword() from pngwutil.c to pngset.c

Changes since the last public release (1.5.25):
  Fixed an out-of-range read in png_check_keyword() (Bug report from
    Qixue Xiao, CVE-2015-8540).
  Corrected copyright dates in source files.
  Moved png_check_keyword() from pngwutil.c to pngset.c
  Added keyword checks to pngset.c (John Bowler).

Libpng-1.6.20 is not vulnerable to CVE-2015-8540 so we're not
releasing 1.6.21 at this time.

Glenn

--001a1139bb78e4b160052719c0bd
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div><div>libpng-1.5.26, 1.4.19, 1.2.56, and 1.0=
.66 are available from<br></div><a href=3D"ftp://ftp.simplesystems.org/pub/=
png/src/">ftp://ftp.simplesystems.org/pub/png/src/</a><br></div>and from<br=
></div><a href=3D"http://libpng.sf.net">http://libpng.sf.net</a><br><br>Cha=
nges since the last public release (1.0.55, 1.2.55, 1.4.18):<br><br>=C2=A0 =
Fixed an out-of-range read in png_check_keyword() (Bug report from<br>=C2=
=A0=C2=A0=C2=A0 Qixue Xiao, CVE-2015-8540).<br>=C2=A0 Corrected copyright d=
ates in source files.<br>=C2=A0 Moved png_check_keyword() from pngwutil.c t=
o pngset.c<br><br>Changes since the last public release (1.5.25):<br>=C2=A0=
 Fixed an out-of-range read in png_check_keyword() (Bug report from<br>=C2=
=A0=C2=A0=C2=A0 Qixue Xiao, CVE-2015-8540).<br>=C2=A0 Corrected copyright d=
ates in source files.<br>=C2=A0 Moved png_check_keyword() from pngwutil.c t=
o pngset.c<br>=C2=A0 Added keyword checks to pngset.c (John Bowler).<br><br=
></div><div>Libpng-1.6.20 is not vulnerable to CVE-2015-8540 so we&#39;re n=
ot<br></div><div>releasing 1.6.21 at this time.<br></div><div><br></div>Gle=
nn<br><div><br></div></div>

--001a1139bb78e4b160052719c0bd--


--===============4598899383975383393==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============4598899383975383393==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
png-mng-announce mailing list
png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/png-mng-announce

--===============4598899383975383393==--