Release libpng version 1.6.47

This commit is contained in:
Cosmin Truta
2025-02-18 11:18:30 +02:00
parent bb7e922914
commit 872555f4ba
17 changed files with 66 additions and 62 deletions

12
CHANGES
View File

@@ -6239,7 +6239,17 @@ Version 1.6.46 [January 23, 2025]
Cleaned up contrib/pngminus: corrected an old typo, removed an old
workaround, and updated the CMake file.
Version 1.6.47 [TODO]
Version 1.6.47 [February 18, 2025]
Modified the behaviour of colorspace chunks in order to adhere
to the new precedence rules formulated in the latest draft of
the PNG Specification.
(Contributed by John Bowler)
Fixed a latent bug in `png_write_iCCP`.
This would have been a read-beyond-end-of-malloc vulnerability,
introduced early in the libpng-1.6.0 development, yet (fortunately!)
it was inaccessible before the above-mentioned modification of the
colorspace precedence rules, due to pre-existing colorspace checks.
(Reported by Bob Friesenhahn; fixed by John Bowler)
Send comments/corrections/commendations to png-mng-implement at lists.sf.net.
Subscription is required; visit