diff --git a/ANNOUNCE b/ANNOUNCE index c75f45b82..6bc50236d 100644 --- a/ANNOUNCE +++ b/ANNOUNCE @@ -1,4 +1,4 @@ -Libpng 1.6.19rc01 - October 23, 2015 +Libpng 1.6.19rc02 - October 29, 2015 This is not intended to be a public release. It will be replaced within a few weeks by a public version or by another test version. @@ -8,20 +8,20 @@ Files available for download: Source files with LF line endings (for Unix/Linux) and with a "configure" script - 1.6.19rc01.tar.xz (LZMA-compressed, recommended) - 1.6.19rc01.tar.gz + 1.6.19rc02.tar.xz (LZMA-compressed, recommended) + 1.6.19rc02.tar.gz Source files with CRLF line endings (for Windows), without the "configure" script - lp1619r01.7z (LZMA-compressed, recommended) - lp1619r01.zip + lp1619r02.7z (LZMA-compressed, recommended) + lp1619r02.zip Other information: - 1.6.19rc01-README.txt - 1.6.19rc01-LICENSE.txt - libpng-1.6.19rc01-*.asc (armored detached GPG signatures) + 1.6.19rc02-README.txt + 1.6.19rc02-LICENSE.txt + libpng-1.6.19rc02-*.asc (armored detached GPG signatures) Changes since the last public release (1.6.18): @@ -106,6 +106,9 @@ Version 1.6.19beta04 [October 15, 2015] Version 1.6.19rc01 [October 23, 2015] No changes. +Version 1.6.19rc02 [October 29, 2015] + Prevent writing over-length PLTE chunk (Cosmin Truta). + Send comments/corrections/commendations to png-mng-implement at lists.sf.net (subscription required; visit https://lists.sourceforge.net/lists/listinfo/png-mng-implement diff --git a/CHANGES b/CHANGES index 27455bcfa..945a7fdff 100644 --- a/CHANGES +++ b/CHANGES @@ -3756,8 +3756,9 @@ Version 1.5.7beta04 [November 17, 2011] Version 1.5.7beta05 [November 25, 2011] Removed "zTXt" from warning in generic chunk decompression function. - Validate time settings passed to pngset() and png_convert_to_rfc1123() - (Frank Busse). + Validate time settings passed to png_set_tIME() and png_convert_to_rfc1123() + (Frank Busse). Note: This prevented CVE-2015-7981 from affecting + libpng-1.5.7 and later. Added MINGW support to CMakeLists.txt Reject invalid compression flag or method when reading the iTXt chunk. Backed out 'simplified' API changes. The API seems too complex and there @@ -5390,6 +5391,9 @@ Version 1.6.19beta04 [October 15, 2015] Version 1.6.19rc01 [October 23, 2015] No changes. +Version 1.6.19rc02 [October 29, 2015] + Prevent writing over-length PLTE chunk (Cosmin Truta). + Send comments/corrections/commendations to png-mng-implement at lists.sf.net (subscription required; visit https://lists.sourceforge.net/lists/listinfo/png-mng-implement diff --git a/CMakeLists.txt b/CMakeLists.txt index ef782f812..aa79121c5 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -261,7 +261,7 @@ endif(NOT WIN32 OR CYGWIN OR MINGW) # SET UP LINKS if(PNG_SHARED) set_target_properties(${PNG_LIB_NAME} PROPERTIES -# VERSION 16.${PNGLIB_RELEASE}.1.6.19rc01 +# VERSION 16.${PNGLIB_RELEASE}.1.6.19rc02 VERSION 16.${PNGLIB_RELEASE}.0 SOVERSION 16 CLEAN_DIRECT_OUTPUT 1) diff --git a/LICENSE b/LICENSE index 8ff1c6860..77ba6ffb3 100644 --- a/LICENSE +++ b/LICENSE @@ -10,7 +10,7 @@ this sentence. This code is released under the libpng license. -libpng versions 1.0.7, July 1, 2000, through 1.6.19rc01, October 23, 2015, are +libpng versions 1.0.7, July 1, 2000, through 1.6.19rc02, October 29, 2015, are Copyright (c) 2000-2002, 2004, 2006-2015 Glenn Randers-Pehrson, and are distributed according to the same disclaimer and license as libpng-1.0.6 with the following individuals added to the list of Contributing Authors: @@ -104,4 +104,4 @@ the additional disclaimers inserted at version 1.0.7. Glenn Randers-Pehrson glennrp at users.sourceforge.net -October 23, 2015 +October 29, 2015 diff --git a/README b/README index 1af35b376..9129c51d4 100644 --- a/README +++ b/README @@ -1,4 +1,4 @@ -README for libpng version 1.6.19rc01 - October 23, 2015 (shared library 16.0) +README for libpng version 1.6.19rc02 - October 29, 2015 (shared library 16.0) See the note about version numbers near the top of png.h See INSTALL for instructions on how to install libpng. diff --git a/configure.ac b/configure.ac index 88cada207..d23f0d09f 100644 --- a/configure.ac +++ b/configure.ac @@ -18,7 +18,7 @@ AC_PREREQ([2.68]) dnl Version number stuff here: -AC_INIT([libpng],[1.6.19rc01],[png-mng-implement@lists.sourceforge.net]) +AC_INIT([libpng],[1.6.19rc02],[png-mng-implement@lists.sourceforge.net]) AC_CONFIG_MACRO_DIR([scripts]) # libpng does not follow GNU file name conventions (hence 'foreign') @@ -39,7 +39,7 @@ dnl automake, so the following is not necessary (and is not defined anyway): dnl AM_PREREQ([1.11.2]) dnl stop configure from automagically running automake -PNGLIB_VERSION=1.6.19rc01 +PNGLIB_VERSION=1.6.19rc02 PNGLIB_MAJOR=1 PNGLIB_MINOR=6 PNGLIB_RELEASE=19 diff --git a/libpng-manual.txt b/libpng-manual.txt index 921463c09..865b2713a 100644 --- a/libpng-manual.txt +++ b/libpng-manual.txt @@ -1,6 +1,6 @@ libpng-manual.txt - A description on how to use and modify libpng - libpng version 1.6.19rc01 - October 23, 2015 + libpng version 1.6.19rc02 - October 29, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -11,7 +11,7 @@ libpng-manual.txt - A description on how to use and modify libpng Based on: - libpng versions 0.97, January 1998, through 1.6.19rc01 - October 23, 2015 + libpng versions 0.97, January 1998, through 1.6.19rc02 - October 29, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -5319,13 +5319,13 @@ Other rules can be inferred by inspecting the libpng source. XVI. Y2K Compliance in libpng -October 23, 2015 +October 29, 2015 Since the PNG Development group is an ad-hoc body, we can't make an official declaration. This is your unofficial assurance that libpng from version 0.71 and -upward through 1.6.19rc01 are Y2K compliant. It is my belief that earlier +upward through 1.6.19rc02 are Y2K compliant. It is my belief that earlier versions were also Y2K compliant. Libpng only has two year fields. One is a 2-byte unsigned integer diff --git a/libpng.3 b/libpng.3 index 75f7b68b7..d41d8d60c 100644 --- a/libpng.3 +++ b/libpng.3 @@ -1,6 +1,6 @@ -.TH LIBPNG 3 "October 23, 2015" +.TH LIBPNG 3 "October 29, 2015" .SH NAME -libpng \- Portable Network Graphics (PNG) Reference Library 1.6.19rc01 +libpng \- Portable Network Graphics (PNG) Reference Library 1.6.19rc02 .SH SYNOPSIS \fB #include \fP @@ -508,7 +508,7 @@ Following is a copy of the libpng-manual.txt file that accompanies libpng. .SH LIBPNG.TXT libpng-manual.txt - A description on how to use and modify libpng - libpng version 1.6.19rc01 - October 23, 2015 + libpng version 1.6.19rc02 - October 29, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -519,7 +519,7 @@ libpng-manual.txt - A description on how to use and modify libpng Based on: - libpng versions 0.97, January 1998, through 1.6.19rc01 - October 23, 2015 + libpng versions 0.97, January 1998, through 1.6.19rc02 - October 29, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -5827,13 +5827,13 @@ Other rules can be inferred by inspecting the libpng source. .SH XVI. Y2K Compliance in libpng -October 23, 2015 +October 29, 2015 Since the PNG Development group is an ad-hoc body, we can't make an official declaration. This is your unofficial assurance that libpng from version 0.71 and -upward through 1.6.19rc01 are Y2K compliant. It is my belief that earlier +upward through 1.6.19rc02 are Y2K compliant. It is my belief that earlier versions were also Y2K compliant. Libpng only has two year fields. One is a 2-byte unsigned integer @@ -6149,7 +6149,7 @@ possible without all of you. Thanks to Frank J. T. Wojcik for helping with the documentation. -Libpng version 1.6.19rc01 - October 23, 2015: +Libpng version 1.6.19rc02 - October 29, 2015: Initially created in 1995 by Guy Eric Schalnat, then of Group 42, Inc. Currently maintained by Glenn Randers-Pehrson (glennrp at users.sourceforge.net). @@ -6172,7 +6172,7 @@ this sentence. This code is released under the libpng license. -libpng versions 1.0.7, July 1, 2000, through 1.6.19rc01, October 23, 2015, are +libpng versions 1.0.7, July 1, 2000, through 1.6.19rc02, October 29, 2015, are Copyright (c) 2000-2002, 2004, 2006-2015 Glenn Randers-Pehrson, and are distributed according to the same disclaimer and license as libpng-1.0.6 with the following individuals added to the list of Contributing Authors: @@ -6266,7 +6266,7 @@ the additional disclaimers inserted at version 1.0.7. Glenn Randers-Pehrson glennrp at users.sourceforge.net -October 23, 2015 +October 29, 2015 .\" end of man page diff --git a/libpngpf.3 b/libpngpf.3 index e141d15a5..cfae7f4d4 100644 --- a/libpngpf.3 +++ b/libpngpf.3 @@ -1,6 +1,6 @@ -.TH LIBPNGPF 3 "October 23, 2015" +.TH LIBPNGPF 3 "October 29, 2015" .SH NAME -libpng \- Portable Network Graphics (PNG) Reference Library 1.6.19rc01 +libpng \- Portable Network Graphics (PNG) Reference Library 1.6.19rc02 (private functions) .SH SYNOPSIS \fB#include \fI"pngpriv.h" diff --git a/png.5 b/png.5 index 5fd57a043..0e42f8e58 100644 --- a/png.5 +++ b/png.5 @@ -1,4 +1,4 @@ -.TH PNG 5 "October 23, 2015" +.TH PNG 5 "October 29, 2015" .SH NAME png \- Portable Network Graphics (PNG) format .SH DESCRIPTION diff --git a/png.c b/png.c index eb9ad3a03..fa73b990e 100644 --- a/png.c +++ b/png.c @@ -14,7 +14,7 @@ #include "pngpriv.h" /* Generate a compiler error if there is an old png.h in the search path. */ -typedef png_libpng_version_1_6_19rc01 Your_png_h_is_not_version_1_6_19rc01; +typedef png_libpng_version_1_6_19rc02 Your_png_h_is_not_version_1_6_19rc02; /* Tells libpng that we have already handled the first "num_bytes" bytes * of the PNG file signature. If the PNG data is embedded into another @@ -775,13 +775,13 @@ png_get_copyright(png_const_structrp png_ptr) #else # ifdef __STDC__ return PNG_STRING_NEWLINE \ - "libpng version 1.6.19rc01 - October 23, 2015" PNG_STRING_NEWLINE \ + "libpng version 1.6.19rc02 - October 29, 2015" PNG_STRING_NEWLINE \ "Copyright (c) 1998-2015 Glenn Randers-Pehrson" PNG_STRING_NEWLINE \ "Copyright (c) 1996-1997 Andreas Dilger" PNG_STRING_NEWLINE \ "Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc." \ PNG_STRING_NEWLINE; # else - return "libpng version 1.6.19rc01 - October 23, 2015\ + return "libpng version 1.6.19rc02 - October 29, 2015\ Copyright (c) 1998-2015 Glenn Randers-Pehrson\ Copyright (c) 1996-1997 Andreas Dilger\ Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc."; diff --git a/png.h b/png.h index 72f66c456..097a0060e 100644 --- a/png.h +++ b/png.h @@ -1,7 +1,7 @@ /* png.h - header file for PNG reference library * - * libpng version 1.6.19rc01, October 23, 2015 + * libpng version 1.6.19rc02, October 29, 2015 * * Copyright (c) 1998-2015 Glenn Randers-Pehrson * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger) @@ -12,7 +12,7 @@ * Authors and maintainers: * libpng versions 0.71, May 1995, through 0.88, January 1996: Guy Schalnat * libpng versions 0.89, June 1996, through 0.96, May 1997: Andreas Dilger - * libpng versions 0.97, January 1998, through 1.6.19rc01, October 23, 2015: Glenn + * libpng versions 0.97, January 1998, through 1.6.19rc02, October 29, 2015: Glenn * See also "Contributing Authors", below. * * Note about libpng version numbers: @@ -252,7 +252,7 @@ * * This code is released under the libpng license. * - * libpng versions 1.0.7, July 1, 2000, through 1.6.19rc01, October 23, 2015, are + * libpng versions 1.0.7, July 1, 2000, through 1.6.19rc02, October 29, 2015, are * Copyright (c) 2000-2002, 2004, 2006-2015 Glenn Randers-Pehrson, and are * distributed according to the same disclaimer and license as libpng-1.0.6 * with the following individuals added to the list of Contributing Authors: @@ -361,13 +361,13 @@ * Y2K compliance in libpng: * ========================= * - * October 23, 2015 + * October 29, 2015 * * Since the PNG Development group is an ad-hoc body, we can't make * an official declaration. * * This is your unofficial assurance that libpng from version 0.71 and - * upward through 1.6.19rc01 are Y2K compliant. It is my belief that + * upward through 1.6.19rc02 are Y2K compliant. It is my belief that * earlier versions were also Y2K compliant. * * Libpng only has two year fields. One is a 2-byte unsigned integer @@ -429,9 +429,9 @@ */ /* Version information for png.h - this should match the version in png.c */ -#define PNG_LIBPNG_VER_STRING "1.6.19rc01" +#define PNG_LIBPNG_VER_STRING "1.6.19rc02" #define PNG_HEADER_VERSION_STRING \ - " libpng version 1.6.19rc01 - October 23, 2015\n" + " libpng version 1.6.19rc02 - October 29, 2015\n" #define PNG_LIBPNG_VER_SONUM 16 #define PNG_LIBPNG_VER_DLLNUM 16 @@ -445,7 +445,7 @@ * PNG_LIBPNG_VER_STRING, omitting any leading zero: */ -#define PNG_LIBPNG_VER_BUILD 01 +#define PNG_LIBPNG_VER_BUILD 02 /* Release Status */ #define PNG_LIBPNG_BUILD_ALPHA 1 @@ -580,7 +580,7 @@ extern "C" { /* This triggers a compiler error in png.c, if png.c and png.h * do not agree upon the version number. */ -typedef char* png_libpng_version_1_6_19rc01; +typedef char* png_libpng_version_1_6_19rc02; /* Basic control structions. Read libpng-manual.txt or libpng.3 for more info. * diff --git a/pngconf.h b/pngconf.h index a40925c00..244bb883e 100644 --- a/pngconf.h +++ b/pngconf.h @@ -1,7 +1,7 @@ /* pngconf.h - machine configurable file for libpng * - * libpng version 1.6.19rc01, July 23, 2015 + * libpng version 1.6.19rc02, July 23, 2015 * * Copyright (c) 1998-2015 Glenn Randers-Pehrson * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger) diff --git a/pngtest.c b/pngtest.c index 1531b5e4c..b6887bd98 100644 --- a/pngtest.c +++ b/pngtest.c @@ -2057,4 +2057,4 @@ main(void) #endif /* Generate a compiler error if there is an old png.h in the search path. */ -typedef png_libpng_version_1_6_19rc01 Your_png_h_is_not_version_1_6_19rc01; +typedef png_libpng_version_1_6_19rc02 Your_png_h_is_not_version_1_6_19rc02; diff --git a/projects/vstudio/readme.txt b/projects/vstudio/readme.txt index d6e096ccc..74113d9d0 100644 --- a/projects/vstudio/readme.txt +++ b/projects/vstudio/readme.txt @@ -1,7 +1,7 @@ VisualStudio instructions -libpng version 1.6.19rc01 - October 23, 2015 +libpng version 1.6.19rc02 - October 29, 2015 Copyright (c) 1998-2010 Glenn Randers-Pehrson diff --git a/projects/vstudio/zlib.props b/projects/vstudio/zlib.props index 872d69b50..07cbb1870 100644 --- a/projects/vstudio/zlib.props +++ b/projects/vstudio/zlib.props @@ -2,7 +2,7 @@