Changelog for
optipng-0.7.7-lp152.3.5.x86_64.rpm :
* Fri Jan 12 2018 pgajdosAATTsuse.com- update to 0.7.7:
* Upgraded minitiff to version 0.2. !! Fixed a buffer overflow vulnerability in the GIF decoder. [Reported by Joonun Jang] !! Fixed an integer overflow vulnerability in the TIFF decoder. [Reported by Jaeseung Choi] ! Fixed the build on macOS High Sierra. [Reported by various users] [Fixed by Yuen Ho Wong and Friedrich Preuss] ! Fixed the build on DJGPP.
* Disallowed out-of-bounds values in rangeset options.- removed upstream patches: - optipng-CVE-2017-1000229.patch - optipng-CVE-2017-16938.patch
* Mon Nov 27 2017 pgajdosAATTsuse.com- security update:
* CVE-2017-16938 [bsc#1069774] + optipng-CVE-2017-16938.patch
* Mon Nov 20 2017 pgajdosAATTsuse.com- security update:
* CVE-2017-1000229 [bsc#1068720] + optipng-CVE-2017-1000229.patch
* Tue Apr 05 2016 pgajdosAATTsuse.com- updated to 0.7.6, fixes CVE-2016-2191
* Mon Apr 27 2015 mpluskalAATTsuse.com- Cleanup spec file with spec-clener- Update dependencies- Enable checks
* Mon Mar 31 2014 pgajdosAATTsuse.com- updated to 0.7.5: ! Fixed various build issues with libpng-1.5 and libpng-1.6.
* Allowed the handling of huge image files (> millions of pixels per row or column) to be independent of the libpng version. + Allowed the option -preserve to save the file ownership (UID/GID) on Unix. (Thanks to Otto Kekäläinen for the suggestion.)- removed libpng16.patch
* Fri Feb 15 2013 pgajdosAATTsuse.com- build also agains libpng16
* libpng16.patch
* Tue Nov 20 2012 pgajdosAATTsuse.com- updated to 0.7.4: !! Fixed the previous fix, which failed to fix the option -fix. (Thanks to Gynvael Coldwind and Mateusz Jurczyk for the report.)
* Mon Sep 24 2012 pgajdosAATTsuse.com- updated to 0.7.3:
* fixed \'OptiPNG Palette Reduction Use-After-Free Vulnerability\' [bnc#780874]
* Tue Aug 07 2012 pgajdosAATTsuse.com- updated to 0.7.1: !! Fixed a regression in the reduction of palette-encoded grayscale images. This regression was introduced in version 0.7. (Thanks to Adam Ciarcinski for the fix.)