From 722645fec597ce54d2fbf23dc53ad4cd330c9d63 Mon Sep 17 00:00:00 2001 From: Glenn Randers-Pehrson Date: Thu, 12 Nov 2015 22:21:35 -0600 Subject: [PATCH] [libpng17] Bump version to 1.7.0beta69 --- ANNOUNCE | 21 +++++++++++---------- CHANGES | 4 ++-- CMakeLists.txt | 2 +- LICENSE | 4 ++-- README | 2 +- configure.ac | 4 ++-- libpng-manual.txt | 8 ++++---- libpng.3 | 18 +++++++++--------- libpngpf.3 | 4 ++-- png.5 | 2 +- png.c | 6 +++--- png.h | 19 ++++++++++--------- pngconf.h | 2 +- pngset.c | 2 +- pngtest.c | 2 +- projects/vstudio/readme.txt | 2 +- projects/vstudio/zlib.props | 2 +- scripts/README.txt | 10 +++++----- scripts/def.c | 2 +- scripts/libpng-config-head.in | 2 +- scripts/libpng.pc.in | 2 +- scripts/makefile.ne12bsd | 2 +- scripts/makefile.netbsd | 2 +- scripts/makefile.openbsd | 2 +- scripts/pnglibconf.h.prebuilt | 4 ++-- scripts/symbols.def | 2 +- 26 files changed, 67 insertions(+), 65 deletions(-) diff --git a/ANNOUNCE b/ANNOUNCE index 72a4f3d28..360f5d1a8 100644 --- a/ANNOUNCE +++ b/ANNOUNCE @@ -1,5 +1,5 @@ -Libpng 1.7.0beta68 - November 12, 2015 +Libpng 1.7.0beta69 - November 13, 2015 This is not intended to be a public release. It will be replaced within a few weeks by a public version or by another test version. @@ -9,20 +9,20 @@ Files available for download: Source files with LF line endings (for Unix/Linux) and with a "configure" script - 1.7.0beta68.tar.xz (LZMA-compressed, recommended) - 1.7.0beta68.tar.gz + 1.7.0beta69.tar.xz (LZMA-compressed, recommended) + 1.7.0beta69.tar.gz Source files with CRLF line endings (for Windows), without the "configure" script - lp170b68.7z (LZMA-compressed, recommended) - lp170b68.zip + lp170b69.7z (LZMA-compressed, recommended) + lp170b69.zip Other information: - 1.7.0beta68-README.txt - 1.7.0beta68-LICENSE.txt - libpng-1.7.0beta68-*.asc (armored detached GPG signatures) + 1.7.0beta69-README.txt + 1.7.0beta69-LICENSE.txt + libpng-1.7.0beta69-*.asc (armored detached GPG signatures) Changes since the last public release (1.6.0): @@ -951,7 +951,8 @@ Version 1.7.0beta67 [November 3, 2015] a minimal safe fix, the issue only arises in non-performance-critical code (bug report by Curtis Leach, fix by John Bowler). Added sPLT chunk support to pngtest.c - Prevent setting or writing over-length PLTE chunk (Cosmin Truta). + Prevent setting or writing over-length PLTE chunk (bug report by + Cosmin Truta) (CVE-2015-8126). Silently truncate over-length PLTE chunk while reading. Fixed some inconsequential cut-and-paste typos in png_set_cHRM_XYZ_fixed(). Clarified COPYRIGHT information to state explicitly that versions @@ -959,7 +960,7 @@ Version 1.7.0beta67 [November 3, 2015] Removed much of the long list of previous versions from png.h and libpng.3. -Version 1.7.0beta68 [November 12, 2015] +Version 1.7.0beta68 [November 13, 2015] Fixed new bug with CRC error after reading an over-length palette (bug report by Cosmin Truta). Cleaned up coding style in png_handle_PLTE(). diff --git a/CHANGES b/CHANGES index 943e3485e..ffe90d58b 100644 --- a/CHANGES +++ b/CHANGES @@ -5259,9 +5259,9 @@ Version 1.7.0beta67 [November 3, 2015] Removed much of the long list of previous versions from png.h and libpng.3. -Version 1.7.0beta68 [November 12, 2015] +Version 1.7.0beta68 [November 13, 2015] Fixed new bug with CRC error after reading an over-length palette - (bug report by Cosmin Truta). + (bug report by Cosmin Truta) (CVE-2015-8126). Cleaned up coding style in png_handle_PLTE(). Send comments/corrections/commendations to png-mng-implement at lists.sf.net diff --git a/CMakeLists.txt b/CMakeLists.txt index 5fd7613fd..c14904f1f 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -261,7 +261,7 @@ endif(NOT WIN32 OR CYGWIN OR MINGW) # SET UP LINKS if(PNG_SHARED) set_target_properties(${PNG_LIB_NAME} PROPERTIES -# VERSION 17.${PNGLIB_RELEASE}.1.7.0beta68 +# VERSION 17.${PNGLIB_RELEASE}.1.7.0beta69 VERSION 17.${PNGLIB_RELEASE}.0 SOVERSION 17 CLEAN_DIRECT_OUTPUT 1) diff --git a/LICENSE b/LICENSE index a27658795..9f552d0d0 100644 --- a/LICENSE +++ b/LICENSE @@ -10,7 +10,7 @@ this sentence. This code is released under the libpng license. -libpng versions 1.0.7, July 1, 2000, through 1.7.0beta68, November 12, 2015, are +libpng versions 1.0.7, July 1, 2000, through 1.7.0beta69, November 13, 2015, are Copyright (c) 2000-2002, 2004, 2006-2015 Glenn Randers-Pehrson, are derived from libpng-1.0.6, and are distributed according to the same disclaimer and license as libpng-1.0.6 with the following individuals @@ -109,4 +109,4 @@ the additional disclaimers inserted at version 1.0.7. Glenn Randers-Pehrson glennrp at users.sourceforge.net -November 12, 2015 +November 13, 2015 diff --git a/README b/README index ca4bd0a13..dae7e9b2c 100644 --- a/README +++ b/README @@ -1,4 +1,4 @@ -README for libpng version 1.7.0beta68 - November 12, 2015 (shared library 17.0) +README for libpng version 1.7.0beta69 - November 13, 2015 (shared library 17.0) See the note about version numbers near the top of png.h See INSTALL for instructions on how to install libpng. diff --git a/configure.ac b/configure.ac index 23c449d55..f471adcd0 100644 --- a/configure.ac +++ b/configure.ac @@ -18,7 +18,7 @@ AC_PREREQ([2.68]) dnl Version number stuff here: -AC_INIT([libpng],[1.7.0beta68],[png-mng-implement@lists.sourceforge.net]) +AC_INIT([libpng],[1.7.0beta69],[png-mng-implement@lists.sourceforge.net]) AC_CONFIG_MACRO_DIR([scripts]) # libpng does not follow GNU file name conventions (hence 'foreign') @@ -40,7 +40,7 @@ dnl automake, so the following is not necessary (and is not defined anyway): dnl AM_PREREQ([1.11.2]) dnl stop configure from automagically running automake -PNGLIB_VERSION=1.7.0beta68 +PNGLIB_VERSION=1.7.0beta69 PNGLIB_MAJOR=1 PNGLIB_MINOR=7 PNGLIB_RELEASE=0 diff --git a/libpng-manual.txt b/libpng-manual.txt index 9f1bcb60b..fdaf75292 100644 --- a/libpng-manual.txt +++ b/libpng-manual.txt @@ -1,6 +1,6 @@ libpng-manual.txt - A description on how to use and modify libpng - libpng version 1.7.0beta68 - November 12, 2015 + libpng version 1.7.0beta69 - November 13, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -11,7 +11,7 @@ libpng-manual.txt - A description on how to use and modify libpng Based on: - libpng versions 0.97, January 1998, through 1.7.0beta68 - November 12, 2015 + libpng versions 0.97, January 1998, through 1.7.0beta69 - November 13, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -4855,7 +4855,7 @@ a set of "safe" limits is applied in pngpriv.h. These can be overridden by application calls to png_set_user_limits(), png_set_user_chunk_cache_max(), and/or png_set_user_malloc_max() that increase or decrease the limits. Also, in libpng-1.5.10 the default width and height limits were increased -from 1,000,000 to 0x7ffffff (i.e., made unlimited). Therefore, the +from 1,000,000 to 0x7fffffff (i.e., made unlimited). Therefore, the limits are now default safe png_user_width_max 0x7fffffff 1,000,000 @@ -5321,7 +5321,7 @@ Since the PNG Development group is an ad-hoc body, we can't make an official declaration. This is your unofficial assurance that libpng from version 0.71 and -upward through 1.7.0beta68 are Y2K compliant. It is my belief that earlier +upward through 1.7.0beta69 are Y2K compliant. It is my belief that earlier versions were also Y2K compliant. Libpng only has two year fields. One is a 2-byte unsigned integer diff --git a/libpng.3 b/libpng.3 index 8a37f59bb..8daf5f4b4 100644 --- a/libpng.3 +++ b/libpng.3 @@ -1,6 +1,6 @@ -.TH LIBPNG 3 "November 12, 2015" +.TH LIBPNG 3 "November 13, 2015" .SH NAME -libpng \- Portable Network Graphics (PNG) Reference Library 1.7.0beta68 +libpng \- Portable Network Graphics (PNG) Reference Library 1.7.0beta69 .SH SYNOPSIS \fB #include \fP @@ -498,7 +498,7 @@ Following is a copy of the libpng-manual.txt file that accompanies libpng. .SH LIBPNG.TXT libpng-manual.txt - A description on how to use and modify libpng - libpng version 1.7.0beta68 - November 12, 2015 + libpng version 1.7.0beta69 - November 13, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -509,7 +509,7 @@ libpng-manual.txt - A description on how to use and modify libpng Based on: - libpng versions 0.97, January 1998, through 1.7.0beta68 - November 12, 2015 + libpng versions 0.97, January 1998, through 1.7.0beta69 - November 13, 2015 Updated and distributed by Glenn Randers-Pehrson Copyright (c) 1998-2015 Glenn Randers-Pehrson @@ -5353,7 +5353,7 @@ a set of "safe" limits is applied in pngpriv.h. These can be overridden by application calls to png_set_user_limits(), png_set_user_chunk_cache_max(), and/or png_set_user_malloc_max() that increase or decrease the limits. Also, in libpng-1.5.10 the default width and height limits were increased -from 1,000,000 to 0x7ffffff (i.e., made unlimited). Therefore, the +from 1,000,000 to 0x7fffffff (i.e., made unlimited). Therefore, the limits are now default safe png_user_width_max 0x7fffffff 1,000,000 @@ -5819,7 +5819,7 @@ Since the PNG Development group is an ad-hoc body, we can't make an official declaration. This is your unofficial assurance that libpng from version 0.71 and -upward through 1.7.0beta68 are Y2K compliant. It is my belief that earlier +upward through 1.7.0beta69 are Y2K compliant. It is my belief that earlier versions were also Y2K compliant. Libpng only has two year fields. One is a 2-byte unsigned integer @@ -5980,7 +5980,7 @@ possible without all of you. Thanks to Frank J. T. Wojcik for helping with the documentation. -Libpng version 1.7.0beta68 - November 12, 2015: +Libpng version 1.7.0beta69 - November 13, 2015: Initially created in 1995 by Guy Eric Schalnat, then of Group 42, Inc. Currently maintained by Glenn Randers-Pehrson (glennrp at users.sourceforge.net). @@ -6005,7 +6005,7 @@ this sentence. This code is released under the libpng license. -libpng versions 1.0.7, July 1, 2000, through 1.7.0beta68, November 12, 2015, are +libpng versions 1.0.7, July 1, 2000, through 1.7.0beta69, November 13, 2015, are Copyright (c) 2000-2002, 2004, 2006-2015 Glenn Randers-Pehrson, are derived from libpng-1.0.6, and are distributed according to the same disclaimer and license as libpng-1.0.6 with the following individuals @@ -6104,7 +6104,7 @@ the additional disclaimers inserted at version 1.0.7. Glenn Randers-Pehrson glennrp at users.sourceforge.net -November 12, 2015 +November 13, 2015 .\" end of man page diff --git a/libpngpf.3 b/libpngpf.3 index 9ec8de7f6..e77f3f660 100644 --- a/libpngpf.3 +++ b/libpngpf.3 @@ -1,6 +1,6 @@ -.TH LIBPNGPF 3 "November 12, 2015" +.TH LIBPNGPF 3 "November 13, 2015" .SH NAME -libpng \- Portable Network Graphics (PNG) Reference Library 1.7.0beta68 +libpng \- Portable Network Graphics (PNG) Reference Library 1.7.0beta69 (private functions) .SH SYNOPSIS \fB#include \fI"pngpriv.h" diff --git a/png.5 b/png.5 index e4688d3db..e7bfffd00 100644 --- a/png.5 +++ b/png.5 @@ -1,4 +1,4 @@ -.TH PNG 5 "November 12, 2015" +.TH PNG 5 "November 13, 2015" .SH NAME png \- Portable Network Graphics (PNG) format .SH DESCRIPTION diff --git a/png.c b/png.c index bf7dcd2fe..0a6553bb9 100644 --- a/png.c +++ b/png.c @@ -15,7 +15,7 @@ #define PNG_SRC_FILE PNG_SRC_FILE_png /* Generate a compiler error if there is an old png.h in the search path. */ -typedef png_libpng_version_1_7_0beta68 Your_png_h_is_not_version_1_7_0beta68; +typedef png_libpng_version_1_7_0beta69 Your_png_h_is_not_version_1_7_0beta69; /* Tells libpng that we have already handled the first "num_bytes" bytes * of the PNG file signature. If the PNG data is embedded into another @@ -699,13 +699,13 @@ png_get_copyright(png_const_structrp png_ptr) #else # ifdef __STDC__ return PNG_STRING_NEWLINE \ - "libpng version 1.7.0beta68 - November 12, 2015" PNG_STRING_NEWLINE \ + "libpng version 1.7.0beta69 - November 13, 2015" PNG_STRING_NEWLINE \ "Copyright (c) 1998-2015 Glenn Randers-Pehrson" PNG_STRING_NEWLINE \ "Copyright (c) 1996-1997 Andreas Dilger" PNG_STRING_NEWLINE \ "Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc." \ PNG_STRING_NEWLINE; # else - return "libpng version 1.7.0beta68 - November 12, 2015\ + return "libpng version 1.7.0beta69 - November 13, 2015\ Copyright (c) 1998-2015 Glenn Randers-Pehrson\ Copyright (c) 1996-1997 Andreas Dilger\ Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc."; diff --git a/png.h b/png.h index 646dca341..7d166f5b3 100644 --- a/png.h +++ b/png.h @@ -1,7 +1,7 @@ /* png.h - header file for PNG reference library * - * libpng version 1.7.0beta68, November 12, 2015 + * libpng version 1.7.0beta69, November 13, 2015 * * Copyright (c) 1998-2015 Glenn Randers-Pehrson * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger) @@ -12,7 +12,8 @@ * Authors and maintainers: * libpng versions 0.71, May 1995, through 0.88, January 1996: Guy Schalnat * libpng versions 0.89, June 1996, through 0.96, May 1997: Andreas Dilger - * libpng versions 0.97, January 1998, through 1.7.0beta68, November 12, 2015: Glenn + * libpng versions 0.97, January 1998, through 1.7.0beta69, November 13, 2015: + * Glenn Randers-Pehrson. * See also "Contributing Authors", below. */ @@ -24,7 +25,7 @@ * * This code is released under the libpng license. * - * libpng versions 1.0.7, July 1, 2000, through 1.7.0beta68, November 12, 2015, are + * libpng versions 1.0.7, July 1, 2000, through 1.7.0beta69, November 13, 2015, are * Copyright (c) 2000-2002, 2004, 2006-2015 Glenn Randers-Pehrson, are * derived from libpng-1.0.6, and are distributed according to the same * disclaimer and license as libpng-1.0.6 with the following individuals @@ -217,13 +218,13 @@ * Y2K compliance in libpng: * ========================= * - * November 12, 2015 + * November 13, 2015 * * Since the PNG Development group is an ad-hoc body, we can't make * an official declaration. * * This is your unofficial assurance that libpng from version 0.71 and - * upward through 1.7.0beta68 are Y2K compliant. It is my belief that + * upward through 1.7.0beta69 are Y2K compliant. It is my belief that * earlier versions were also Y2K compliant. * * Libpng only has two year fields. One is a 2-byte unsigned integer @@ -285,9 +286,9 @@ */ /* Version information for png.h - this should match the version in png.c */ -#define PNG_LIBPNG_VER_STRING "1.7.0beta68" +#define PNG_LIBPNG_VER_STRING "1.7.0beta69" #define PNG_HEADER_VERSION_STRING \ - " libpng version 1.7.0beta68 - November 12, 2015\n" + " libpng version 1.7.0beta69 - November 13, 2015\n" #define PNG_LIBPNG_VER_SONUM 17 #define PNG_LIBPNG_VER_DLLNUM 17 @@ -301,7 +302,7 @@ * PNG_LIBPNG_VER_STRING, omitting any leading zero: */ -#define PNG_LIBPNG_VER_BUILD 68 +#define PNG_LIBPNG_VER_BUILD 69 /* Release Status */ #define PNG_LIBPNG_BUILD_ALPHA 1 @@ -561,7 +562,7 @@ extern "C" { /* This triggers a compiler error in png.c, if png.c and png.h * do not agree upon the version number. */ -typedef char* png_libpng_version_1_7_0beta68; +typedef char* png_libpng_version_1_7_0beta69; /* Basic control structions. Read libpng-manual.txt or libpng.3 for more info. * diff --git a/pngconf.h b/pngconf.h index 5a1b9c75e..4a588f51d 100644 --- a/pngconf.h +++ b/pngconf.h @@ -1,7 +1,7 @@ /* pngconf.h - machine configurable file for libpng * - * libpng version 1.7.0beta68, November 12, 2015 + * libpng version 1.7.0beta69, November 13, 2015 * * Copyright (c) 1998-2015 Glenn Randers-Pehrson * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger) diff --git a/pngset.c b/pngset.c index 5e2656ad6..8308e7387 100644 --- a/pngset.c +++ b/pngset.c @@ -1601,7 +1601,7 @@ png_set_user_limits (png_structrp png_ptr, png_uint_32 user_width_max, { /* Images with dimensions larger than these limits will be * rejected by png_set_IHDR(). To accept any PNG datastream - * regardless of dimensions, set both limits to 0x7ffffffL. + * regardless of dimensions, set both limits to 0x7fffffffL. */ if (png_ptr == NULL) return; diff --git a/pngtest.c b/pngtest.c index e6ce25fdb..126b847ff 100644 --- a/pngtest.c +++ b/pngtest.c @@ -2031,4 +2031,4 @@ main(void) #endif /* Generate a compiler error if there is an old png.h in the search path. */ -typedef png_libpng_version_1_7_0beta68 Your_png_h_is_not_version_1_7_0beta68; +typedef png_libpng_version_1_7_0beta69 Your_png_h_is_not_version_1_7_0beta69; diff --git a/projects/vstudio/readme.txt b/projects/vstudio/readme.txt index 2da3d70ea..d1b66260f 100644 --- a/projects/vstudio/readme.txt +++ b/projects/vstudio/readme.txt @@ -1,7 +1,7 @@ VisualStudio instructions -libpng version 1.7.0beta68 - November 12, 2015 +libpng version 1.7.0beta69 - November 13, 2015 Copyright (c) 1998-2010 Glenn Randers-Pehrson diff --git a/projects/vstudio/zlib.props b/projects/vstudio/zlib.props index 89f7c7dc4..0ee55dfdc 100644 --- a/projects/vstudio/zlib.props +++ b/projects/vstudio/zlib.props @@ -2,7 +2,7 @@