GraphicsMagick 1.3.17 is released

Bob Friesenhahn <[email protected]> Sun, 14 Oct 2012 11:18:34 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.announce
Message-ID <[email protected]>
GraphicsMagick 1.3.17 is now available.  This release includes both 
critical bug fixes and significant feature improvements. 
All users are recommended to update to this release.  As usual, this 
release is API and ABI compatible with previous 1.3.X releases so it 
should be a drop-in replacement.

Please visit the web site at http://www.graphicsmagick.org/ to learn 
more about GraphicsMagick.

Of particular note in this release, is that the configure script 
supports a --enable-quantum-library-names option which allows shared 
libraries from different quantum build depths to be installed in 
parallel by including the quantum depth in the shared library name. 
This will allow OS distributions to satisfy both web and 
scientific/publishing users by providing a "deep" package for users 
who need more precision.

As a note for those building the software for x86-64 (AMD64) systems, 
or who have added the -mfpmath=sse option to enable floating point 
math via SSE, it has been discovered that a GCC bug is severely 
inhibiting the performance of several key algorithms on this popular 
architecture (e.g. by a factor of 2-3X).  Adding the 
'-frename-registers' option to CFLAGS avoids the bug but is documented 
to make the software more difficult to debug.

The following are the major changes in this release:

Security Fixes:

   * PNG: Fix for CVE-2012-3438. The Magick_png_malloc function in
     coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper
     variable type for the allocation size, which might allow remote
     attackers to cause a denial of service (crash) via a crafted PNG
     file that triggers incorrect memory allocation.

   * Automake (derived): Fix for CVE-2012-3386: The "make distcheck"
     rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants
     world-writable permissions to the extraction directory, which
     introduces a race condition that allows local users to execute
     arbitrary code via unspecified vectors.

Bug fixes:

   * PNG: Reading sub-8-bit palette images is fixed (images looked
     stretched).

   * SVG: Fixed bug which allowed MVG and SVG files with long vector
     paths to crash the software.

   * SVG: Ignore XML headers rather than rendering them as text.

   * MVG/SVG/WMF/-draw: It is now possible to draw a plain ','
     character.

   * WMF: Fixed a bug which caused wrong centered-text placement.

   * import: Return status was inverted.

   * configure: Don't force that liblzma is used just because libtiff
     is used.

New Features:

   * The configure script now supports a --enable-quantum-library-names
     option to enable that shared library name includes quantum depth
     to allow shared libraries with different quantum depths to
     co-exist in same directory (only one can be used for development).

   * JNX: Support is added for reading the Garmin proprietary Image
     Format.

   * BMP: Support an alpha channel in uncompressed 32-bit BMP.

Feature improvements:

   * -lat: The adaptive threshold algorithm is replaced with a new
      algorithm which scales linearly (rather than quadratically) with
      area size.

   * Tests: Test suite is re-written to use TAP-based tests.

   * GIF: Reader tries to be better at detecting and reporting
     failures.

Performance Improvements:

   * -lat: Adaptive threshold is much faster with large area sizes.

Windows Delegate Updates:

   * Dcraw 9.16 is now included in the build (with JPEG and JPEG2000
     support).

   * Libxml2 is updated to the 2.9.0 release.

   * Libtiff is updated to the 4.0.3 release.

   * Lcms2 is updated to the 2.4 release.

   * Libpng is updated to the 1.5.13 release.

Behavior Changes:

   * Loading modules is only supported for the modules build.
     Previously any build using shared libraries could load modules.

   * Bundled libltdl is now configured as 'installable' rather than
     'convenience'.

   * -enhance: Only filter based on color channels (ignore opacity).

   * BrowseDelegate: Web browser (for viewing help information) now
     defaults to 'xdg-open', but if it is not found, then configure
     will search for firefox, google-chrome, mozilla (in that order).

Bob
-- 
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/

------------------------------------------------------------------------------
Don't let slow site performance ruin your business. Deploy New Relic APM
Deploy New Relic app performance management and know exactly
what is happening inside your Ruby, Python, PHP, Java, and .NET app
Try New Relic at no cost today and get our sweet Data Nerd shirt too!
http://p.sf.net/sfu/newrelic-dev2dev