Security update to 1.2.35: Fix an uninitialized data bug; CVE-2009-0040.

This commit is contained in:
naddy 2009-03-04 20:17:16 +00:00
parent eb8fa7b09e
commit ad59f1741b
5 changed files with 14 additions and 18 deletions

View File

@ -1,11 +1,11 @@
# $OpenBSD: Makefile,v 1.70 2008/12/02 16:45:59 naddy Exp $
# $OpenBSD: Makefile,v 1.71 2009/03/04 20:17:16 naddy Exp $
COMMENT= library for manipulating PNG images
VERSION= 1.2.33
VERSION= 1.2.35
DISTNAME= libpng-${VERSION}
PKGNAME= png-${VERSION}
SHARED_LIBS= png 8.0
SHARED_LIBS= png 8.1
CATEGORIES= graphics
MASTER_SITES= ${MASTER_SITE_SOURCEFORGE:=libpng/}
@ -27,7 +27,4 @@ MAKE_FLAGS= SHLIB_MAJOR=${LIBpng_VERSION:R} \
SHLIB_MINOR=${LIBpng_VERSION:E} \
PNGLIB_VERSION=${VERSION}
post-extract:
@rm -f ${WRKSRC}/*.orig
.include <bsd.port.mk>

View File

@ -1,5 +1,5 @@
MD5 (libpng-1.2.33.tar.gz) = OLF0oO73J+rMw+WjywO4Xw==
RMD160 (libpng-1.2.33.tar.gz) = CQXUqxSzfpfJPJ0c1kvNgStzjzc=
SHA1 (libpng-1.2.33.tar.gz) = Xj/YLe66xgGr0cUPrJlmHFDI73s=
SHA256 (libpng-1.2.33.tar.gz) = wN2N85ERb5EN2K52O2xonmTXQwWxWXP31VzxKVillSQ=
SIZE (libpng-1.2.33.tar.gz) = 800321
MD5 (libpng-1.2.35.tar.gz) = jKYkaTClfVvnrcfE5/teAA==
RMD160 (libpng-1.2.35.tar.gz) = wFGD+xERUzNSrJRzLypiDd4bvLU=
SHA1 (libpng-1.2.35.tar.gz) = tXR1qwX4wtoa1EDL1bAH5iPx82A=
SHA256 (libpng-1.2.35.tar.gz) = HaXIAJbooBSRHgD6tGYcD3fOUjrk1BMIgV8wfucJ/H8=
SIZE (libpng-1.2.35.tar.gz) = 802267

View File

@ -1,4 +1,4 @@
$OpenBSD: patch-scripts_libpng_pc_in,v 1.13 2008/12/02 16:45:59 naddy Exp $
$OpenBSD: patch-scripts_libpng_pc_in,v 1.14 2009/03/04 20:17:16 naddy Exp $
--- scripts/libpng.pc.in.orig Sat Sep 8 05:23:01 2007
+++ scripts/libpng.pc.in Wed Oct 3 17:20:11 2007
@@ -1,10 +1,10 @@
@ -10,7 +10,7 @@ $OpenBSD: patch-scripts_libpng_pc_in,v 1.13 2008/12/02 16:45:59 naddy Exp $
Name: libpng
Description: Loads and saves PNG files
Version: 1.2.33
Version: 1.2.35
-Libs: -L${libdir} -lpng12
+Libs: -L${libdir} -lpng -lz -lm
Cflags: -I${includedir}

View File

@ -1,4 +1,4 @@
$OpenBSD: patch-scripts_makefile_openbsd,v 1.26 2008/12/02 16:45:59 naddy Exp $
$OpenBSD: patch-scripts_makefile_openbsd,v 1.27 2009/03/04 20:17:16 naddy Exp $
--- scripts/makefile.openbsd.orig Sat Sep 8 05:23:02 2007
+++ scripts/makefile.openbsd Wed Oct 3 17:20:11 2007
@@ -4,11 +4,12 @@
@ -12,7 +12,7 @@ $OpenBSD: patch-scripts_makefile_openbsd,v 1.26 2008/12/02 16:45:59 naddy Exp $
+DOCDIR= ${PREFIX}/share/doc/png
-SHLIB_MAJOR= 0
-SHLIB_MINOR= 1.2.33
-SHLIB_MINOR= 1.2.35
LIB= png
SRCS= png.c pngerror.c pngget.c pngmem.c pngpread.c \
@ -25,7 +25,7 @@ $OpenBSD: patch-scripts_makefile_openbsd,v 1.26 2008/12/02 16:45:59 naddy Exp $
MAN= libpng.3 libpngpf.3 png.5
-DOCS = ANNOUNCE CHANGES INSTALL KNOWNBUG LICENSE README TODO Y2KINFO libpng.txt
+DOCS = libpng-1.2.33.txt
+DOCS = libpng-1.2.35.txt
+all: ${_LIBS} libpng-config libpng.pc
+

View File

@ -1,4 +1,4 @@
@comment $OpenBSD: PLIST,v 1.22 2007/10/06 19:33:28 naddy Exp $
@comment $OpenBSD: PLIST,v 1.23 2009/03/04 20:17:16 naddy Exp $
%%SHARED%%
bin/libpng-config
include/libpng/
@ -7,7 +7,6 @@ include/libpng/pngconf.h
lib/libpng.a
lib/pkgconfig/
lib/pkgconfig/libpng.pc
@endfake
@man man/cat3/libpng.0
@man man/cat3/libpngpf.0
@man man/cat5/png.0