libpng-1.2.59rc01, 1.4.22rc01, 1.5.30rc01, and 1.6.33rc01 are available
Glenn Randers-Pehrson <[email protected]>
| Newsgroups | gmane.comp.graphics.png.devel |
|---|---|
| Message-ID | <CA+PdXctF9NS_WBiJjwpdvhZmurYSgvysZTNya-TGfnesz3eZUA@mail.gmail.com> |
libpng-1.2.59rc01, 1.4.22rc01, 1.5.30rc01, and 1.6.33rc01 are available from
https://ftp-osl.osuosl.org/pub/libpng/src/beta/
ftp://ftp-osl.osuosl.org/pub/libpng/src/beta/
http://libpng.download/src/beta/
and from
http://libpng.sf.net
I believe that the "uninitialized value" problems are harmless.
Version 1.2.59rc01 [September 20, 2017]
Initialize memory allocated by png_inflate to zero, using memset, to
stop an oss-fuzz "use of uninitialized value" detection in png_set_text_2()
due to truncated iTXT or zTXT chunk.
version 1.4.22rc01 [September 20, 2017]
Initialize memory allocated by png_inflate to zero, using memset, to
stop an oss-fuzz "use of uninitialized value" detection in png_set_text_2()
due to truncated iTXT or zTXT chunk.
Version 1.5.30rc01 [September 20, 2017]
Initialize memory allocated by png_inflate to zero, using memset, to
stop an oss-fuzz "use of uninitialized value" detection in png_set_text_2()
due to truncated iTXT or zTXT chunk.
Version 1.6.33rc01 [September 20, 2017]
Initialize memory allocated by png_inflate to zero, using memset, to
stop an oss-fuzz "use of uninitialized value" detection in png_set_text_2()
due to truncated iTXT or zTXT chunk.
Initialize memory allocated by png_read_buffer to zero, using memset, to
stop an oss-fuzz "use of uninitialized value" detection in
png_icc_check_tag_table() due to truncated iCCP chunk.
Removed a redundant test (suggested by "irwir" in Github issue #180).
Glenn
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot