libpng: security bump to version 1.6.16
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 24 Dec 2014 12:21:03 +0000 (09:21 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Wed, 24 Dec 2014 13:59:02 +0000 (14:59 +0100)
Fixes a buffer overflow which may allow an attacker to gain write
access to memory.
CVE requested but not yet assigned.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/libpng/libpng.hash
package/libpng/libpng.mk

index 37f60679c3b04c81bb90e9a31453093093a04449..d0027c7b5fa112477d08913a78ceff3cec1cbf7e 100644 (file)
@@ -1,3 +1,3 @@
-# From http://sourceforge.net/projects/libpng/files/libpng16/1.6.15/
-md5    a95cb387c53215b034203b41ec57c7e5        libpng-1.6.15.tar.xz
-sha1   bddeac8ca97fbcf54d6d32c6eefed5d94b49df88        libpng-1.6.15.tar.xz
+# From http://sourceforge.net/projects/libpng/files/libpng16/1.6.16/
+md5    23b7286b5d4a86de950fd2ffc5cac742        libpng-1.6.16.tar.xz
+sha1   31855a8438ae795d249574b0da15b34eb0922e13        libpng-1.6.16.tar.xz
index 67bf14196ac7c0d4a934883395ca7d2572ea8339..2f53a95d9002c6e4fbaffbe4006316680266c121 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBPNG_VERSION = 1.6.15
+LIBPNG_VERSION = 1.6.16
 LIBPNG_SERIES = 16
 LIBPNG_SOURCE = libpng-$(LIBPNG_VERSION).tar.xz
 LIBPNG_SITE = http://downloads.sourceforge.net/project/libpng/libpng${LIBPNG_SERIES}/$(LIBPNG_VERSION)