Skip to content

Update libpng16 from 1.6.34 to 1.6.37 #1167

Merged
merged 2 commits into from
Jul 9, 2019

Conversation

pmenzel
Copy link
Collaborator

@pmenzel pmenzel commented Jul 9, 2019

Tested on rabammel.

From the [Web site][1]:

> libpng versions 1.6.36 and earlier have a use-after-free bug in the
> simplified libpng API png_image_free(). It has been assigned ID
> CVE-2019-7317. The vulnerability is fixed in version 1.6.37, released
> on 15 April 2019.

[1]: http://www.libpng.org/pub/png/libpng.html
The `mee_install_post()` function is actually not present in the
installed package, and seems to have been added later.

Fixes: d53ef08 (libpng16: Add version 1.6.34)
@pmenzel pmenzel merged commit 893c00d into master Jul 9, 2019
Sign in to join this conversation on GitHub.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant