浏览代码

libpng: security bump to version 1.6.19

Fixes:
png_set_PLTE/png_get_PLTE functions failed to check for
an out-of-range palette when reading or writing PNG files with a bit_depth
less than 8.

CVE not yet assigned.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Gustavo Zacarias 9 年之前
父节点
当前提交
e50c333c35
共有 2 个文件被更改,包括 4 次插入4 次删除
  1. 3 3
      package/libpng/libpng.hash
  2. 1 1
      package/libpng/libpng.mk

+ 3 - 3
package/libpng/libpng.hash

@@ -1,3 +1,3 @@
-# From http://sourceforge.net/projects/libpng/files/libpng16/1.6.18/
-md5	6a57c8e0f5469b9c9949a4b43d57b3a1	libpng-1.6.18.tar.xz
-sha1	c6e06510d30beba08c96c468ab269fafb2bb256f	libpng-1.6.18.tar.xz
+# From http://sourceforge.net/projects/libpng/files/libpng16/1.6.19/
+md5	1e6a458429e850fc93c1f3b6dc00a48f	libpng-1.6.19.tar.xz
+sha1	483d72ced11c9258f9d1119105273d9af9ff151c	libpng-1.6.19.tar.xz

+ 1 - 1
package/libpng/libpng.mk

@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBPNG_VERSION = 1.6.18
+LIBPNG_VERSION = 1.6.19
 LIBPNG_SERIES = 16
 LIBPNG_SOURCE = libpng-$(LIBPNG_VERSION).tar.xz
 LIBPNG_SITE = http://downloads.sourceforge.net/project/libpng/libpng${LIBPNG_SERIES}/$(LIBPNG_VERSION)