Fix - double free() in BMP handler (CVE-2005-0891), - endless loop (CVE-2005-2975) and - integer overflows in XPM loader (CVE-2005-2976, CVE-2005-3186). From Ubuntu.
buffer overflow with the XPM decoder, and integer overflow with the ICO decoder. CAN-2004-0753, CAN-2004-0782, CAN-2004-0788