Update package to version 1.6.40

This commit is contained in:
jxy_git 2023-07-13 14:39:59 +08:00
parent 8693fbca6e
commit 98a9ad08e7
4 changed files with 5 additions and 26 deletions

View File

@ -1,23 +0,0 @@
From a0ca4293454ef65e67efca5dc440c601d2835e90 Mon Sep 17 00:00:00 2001
From: tangyaofang <tangyaofang6666@163.com>
Date: Mon, 10 Jun 2019 11:30:15 +0800
Subject: [PATCH] Repair of CVE-2019-6129
---
contrib/tools/pngcp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/contrib/tools/pngcp.c b/contrib/tools/pngcp.c
index 16d4e7f4d..a02d5b7ff 100644
--- a/contrib/tools/pngcp.c
+++ b/contrib/tools/pngcp.c
@@ -506,7 +506,7 @@ static void
display_clean_read(struct display *dp)
{
if (dp->read_pp != NULL)
- png_destroy_read_struct(&dp->read_pp, NULL, NULL);
+ png_destroy_read_struct(&dp->read_pp, (dp->ip!=NULL ? &dp->ip : NULL), NULL);
if (dp->fp != NULL)
{

Binary file not shown.

BIN
libpng-1.6.40.tar.gz Normal file

Binary file not shown.

View File

@ -1,7 +1,7 @@
Name: libpng Name: libpng
Epoch: 2 Epoch: 2
Version: 1.6.38 Version: 1.6.40
Release: 2 Release: 1
Summary: A library of functions for manipulating PNG image format files Summary: A library of functions for manipulating PNG image format files
License: zlib License: zlib
URL: http://www.libpng.org/pub/png/libpng.html URL: http://www.libpng.org/pub/png/libpng.html
@ -10,7 +10,6 @@ Source1: pngusr.dfa
Patch0: libpng-multilib.patch Patch0: libpng-multilib.patch
Patch1: libpng-fix-arm-neon.patch Patch1: libpng-fix-arm-neon.patch
Patch2: CVE-2019-6129.patch
BuildRequires: zlib-devel autoconf automake libtool BuildRequires: zlib-devel autoconf automake libtool
@ -89,6 +88,9 @@ make check
%{_mandir}/man*/* %{_mandir}/man*/*
%changelog %changelog
* Thu Jul 13 2023 jiangxinyu <jiangxinyu@kylinoss.cn> - 1.6.40-1
- Update package to version 1.6.40
* Thu Dec 15 2022 zhouwenpei <zhouwenpei1@h-partners.com> - 1.6.38-2 * Thu Dec 15 2022 zhouwenpei <zhouwenpei1@h-partners.com> - 1.6.38-2
- remove example.c from help - remove example.c from help