|
|
Message-ID: <87v77o9i0v.fsf@gentoo.org>
Date: Tue, 29 Sep 2026 16:47:12 +0100
From: Sam James <sam@...too.org>
To: oss-security@...ts.openwall.com
Subject: Re: libpng 1.6.59: Use-after-free vulnerability
fixed: CVE-2026-46675
Cosmin Truta <ctruta@...il.com> writes:
> Hello, everyone,
Hi Cosmin,
>
> libpng 1.6.59 has been released, fixing a medium-severity
> use-after-free vulnerability in the sequential reader, present since
> libpng 1.6.0. It affects applications that call png_read_end without
> first starting to read the image rows.
>
> Users should either upgrade to libpng 1.6.59 or apply the fix
> described below.
>
> [...]
I can't find a tarball for libpng-1.6.59 in the usual places:
https://sourceforge.net/projects/libpng/files/libpng16/ has no 1.6.59
dir and http://libpng.download/src linked from the README in the repo
has no recent releases.
Is there a plan to make an official tarball available, or to use the
GitHub autogenerated ones going forward? The latter is unfortunate if so
because they're not guaranteed to be stable (and can't be signed, though
libpng releases aren't signed at the moment; was going to file a bug
asking about that).
Cheers!
sam
Download attachment "signature.asc" of type "application/pgp-signature" (419 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.