Subject: CVS commit: pkgsrc/graphics/png
From: Thomas Klausner
Date: 2012-02-18 16:42:57
Message id: 20120218154257.C2269175DD@cvs.netbsd.org

Log Message:
Update to 1.5.9rc01, which includes the official patch for CVE-2011-3026.

Version 1.5.9beta01 [February 3, 2012]
  Rebuilt configure scripts in the tar distributions.

Version 1.5.9beta02 [February 16, 2012]
  Removed two unused definitions from scripts/pnglibconf.h.prebuilt
  Removed some unused arrays (with #ifdef) from png_read_push_finish_row().
  Removed tests for no-longer-used *_EMPTY_PLTE_SUPPORTED from pngstruct.h

Version 1.5.9rc01 [February 17, 2012]
  Fixed CVE-2011-3026 buffer overrun bug.  Deal more correctly with the test
    on iCCP chunk length. Also removed spurious casts that may hide problems
    on 16-bit systems.

Files:
RevisionActionfile
1.145modifypkgsrc/graphics/png/Makefile
1.92modifypkgsrc/graphics/png/distinfo
1.1removepkgsrc/graphics/png/patches/patch-CVE-2011-3026