Cosmin Truta <[email protected]> writes:

> Hello, everyone,

Hi Cosmin,

>
> libpng 1.6.59 has been released, fixing a medium-severity
> use-after-free vulnerability in the sequential reader, present since
> libpng 1.6.0. It affects applications that call png_read_end without
> first starting to read the image rows.
>
> Users should either upgrade to libpng 1.6.59 or apply the fix
> described below.
>
> [...]

I can't find a tarball for libpng-1.6.59 in the usual places:
https://sourceforge.net/projects/libpng/files/libpng16/ has no 1.6.59
dir and http://libpng.download/src linked from the README in the repo
has no recent releases.

Is there a plan to make an official tarball available, or to use the
GitHub autogenerated ones going forward? The latter is unfortunate if so
because they're not guaranteed to be stable (and can't be signed, though
libpng releases aren't signed at the moment; was going to file a bug
asking about that).

Cheers!
sam

Attachment: signature.asc
Description: PGP signature

Reply via email to