Bug 112728 - update ports/graphics/png to 1.2.17
Summary: update ports/graphics/png to 1.2.17
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Andrey A. Chernov
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-05-17 08:00 UTC by Eygene Ryabinkin
Modified: 2007-05-18 16:00 UTC (History)
1 user (show)

See Also:


Attachments
file.diff (4.17 KB, patch)
2007-05-17 08:00 UTC, Eygene Ryabinkin
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Eygene Ryabinkin 2007-05-17 08:00:11 UTC
According to
http://www.FreeBSD.org/ports/portaudit/4cb9c513-03ef-11dc-a51d-0019b95d4f14.html
a DoS was discovered in the libpng code.

New libpng 1.2.17 is out and
http://www.mirrorservice.org/sites/download.sourceforge.net/pub/sourceforge/l/li/libpng/libpng-1.2.17-ADVISORY.txt
says that the 1.2.17 had received the fix.

Fix: The quick patch that has no new features, but just updates the port
and fixes its compilation follows.

The patch files/patch-ae fixes the very strange code at the pnggccrd.c
that I can classify only as incorrect. It is very strange to see
it in the release: sources just should not compile.
How-To-Repeat: 
Look at the above URLs.
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2007-05-17 08:00:25 UTC
Responsible Changed
From-To: freebsd-ports-bugs->ache

Over to maintainer
Comment 2 Eygene Ryabinkin 2007-05-18 09:36:47 UTC
Thu, May 17, 2007 at 07:00:11AM +0000, FreeBSD-gnats-submit@FreeBSD.org wrote:
> Thank you very much for your problem report.
> It has the internal identification `ports/112728'.
> The individual assigned to look at your
> report is: freebsd-ports-bugs. 
> 
> You can access the state of your problem report at any time
> via this link:
> 
> http://www.freebsd.org/cgi/query-pr.cgi?pr=112728

Seems like this PR is outdated by ports/112725. Moving the
discuission there.

This PR can be safely closed, sorry for the noise.
-- 
Eygene
Comment 3 Mark Linimon freebsd_committer freebsd_triage 2007-05-18 16:00:20 UTC
State Changed
From-To: open->closed

See ports/112725.