News and History of the PNG Development Group from 2012
Herein lie news items and historical stuff primarily of interest to the
Portable Network Graphics Development Group itself. Feel free to poke
around even if you're not a member, though. Note that some of the links,
particularly the older ones, are broken; in some cases this is explained by
later entries. Other links (CompuServe, tcg.arl.mil) have fallen prey to
reorganizations or upgrades; should they ever reappear, the entries below
will be updated as needed.
Keep in mind that this is history here...
- current - see here
- 1 February 2012 - libpng 1.5.8
is released with a fix for a one-byte
buffer-overrun bug
(CVE-2011-3464) in
png_formatted_warning(). This can cause a crash in certain
cases (e.g., Apple apps compiled with -fstack-protector), and
it could conceivably result in execution of hostile
code, though no exploit is currently known to exist. The bug
appears to have been introduced in libpng 1.5.4.
- 29 January 2012 - zlib 1.2.6
is released with a number of new features and improvements, particularly
in the gz* convenience functions for gzip streams and in the
low-level deflate functions.
Here are some related PNG pages at this site:
Last modified 3 February 2012.
Copyright © 1995-2012 Greg Roelofs.