Changelog for libpng12-0-1.2.57-73.1.x86_64.rpm :
Wed Jan 31 13:00:00 2018
- check with -j1, be explicit

Tue Jan 30 13:00:00 2018
- Fix SRPM group and grammar issues.

Mon Jan 2 13:00:00 2017
- updated to 1.2.57: fixes CVE-2016-10087

Thu Dec 17 13:00:00 2015
- updated to 1.2.56:
Fixed an out-of-range read in png_check_keyword() (Bug report from
Qixue Xiao, CVE-2015-8540).
Added keyword checks to pngset.c

Thu Dec 3 13:00:00 2015
- updated to 1.2.55:
Avoid potential pointer overflow in png_handle_iTXt(), png_handle_zTXt(),
png_handle_sPLT(), and png_handle_pCAL() (Bug report by John Regehr).
Fixed incorrect implementation of png_set_PLTE() that uses png_ptr
not info_ptr, that left png_set_PLTE() open to the CVE-2015-8126

Fri Nov 13 13:00:00 2015
- updated to 1.2.54

Fri Aug 7 14:00:00 2015
- build in build section

Fri Feb 27 13:00:00 2015
- updated to 1.2.53:
Issue a png_error() instead of a png_warning() when width is
potentially too large for the architecture, in case the calling
application has overridden the default 1,000,000-column limit
(fixes CVE-2014-9495 and CVE-2015-0973).
Display user limits in the output from pngtest.
Changed PNG_USER_CHUNK_MALLOC_MAX from unlimited to 8,000,000.
This can only be changed at library-build time. It only
affects the maximum memory that can be allocated to an
ancillary chunk; it does not limit the size of IDAT
data, which is instead limited by PNG_USER_WIDTH_MAX.

Mon Jan 19 13:00:00 2015
- Fix CVE-2013-7354.patch, include limits.h for INT_MAX

Thu Nov 20 13:00:00 2014
- updated to 1.2.52:

* Avoid out-of-bounds memory access while checking version string.

Tue Apr 22 14:00:00 2014
- security update:

* CVE-2013-7353.patch [bnc#873124]

* CVE-2013-7354.patch [bnc#873123]

Fri Feb 7 13:00:00 2014
- updated to 1.2.51:
Ignore, with a warning, out-of-range value of num_trans in png_set_tRNS().
Replaced AM_CONFIG_HEADER(config.h) with
AC_CONFIG_HEADERS([config.h]) in
Changed default value of PNG_USER_CACHE_MAX from 0 to 32767 in pngconf.h.
Avoid a possible memory leak in contrib/gregbook/readpng.c
Revised libpng.3 so that \"doclifter\" can process it.
Changed \'\"%s\"m\' to \'\"%s\" m\' in png_debug macros to improve portability
among compilers.
Rebuilt the configure scripts with autoconf-2.69 and automake-1.14.1
Removed potentially misleading warning from png_check_IHDR().
Quiet set-but-not-used warnings in pngset.c
Quiet an uninitialized memory warning from VC2013 in png_get_png().
Quiet unused variable warnings from clang by porting PNG_UNUSED() from
Added -DZ_SOLO to CFLAGS in contrib/pngminim/
Added an #ifdef PNG_FIXED_POINT_SUPPORTED/#endif in pngset.c

Wed Apr 17 14:00:00 2013
- add conflicts in -32bit package

Mon Apr 15 14:00:00 2013
- Added url as source.
Please see

Wed Oct 24 14:00:00 2012
- Add missing baselib requires for compat-devel-32bit

Wed Jul 11 14:00:00 2012
- updated to 1.2.50:
Changed \"a+w\" to \"u+w\" in to fix CVE-2012-3386.

Thu Mar 29 14:00:00 2012
- updated to 1.2.49: [bnc#754745]
Revised png_set_text_2() to avoid potential memory corruption (fixes
Prevent PNG_EXPAND+PNG_SHIFT doing the shift twice.

Wed Mar 14 13:00:00 2012
- updated to 1.2.48:

* fixed CVE-2011-3045 [bnc#752008]

Mon Feb 20 13:00:00 2012
- updated to 1.2.47:

* fixed CVE-2011-3026 [bnc#747311]

Thu Dec 1 13:00:00 2011
- Name field shouldn\'t contain a macro

Thu Dec 1 13:00:00 2011
- add libtool as buildrequire to avoid implicit dependency

Wed Oct 5 14:00:00 2011
- cross-build fix: use %configure macro

Tue Jul 12 14:00:00 2011
- updated to 1.2.46:

* fixed CVE-2011-2501 [bnc#702578]

Mon Aug 30 14:00:00 2010
- fix baselibs.conf after previous change

Thu Jul 29 14:00:00 2010
- add devel packages to baselibs.conf [bnc#625883]

Mon Jun 28 14:00:00 2010
- updated to 1.2.44: fixed libpng overflow (CVE-2010-1205)
and memory leak [bnc#617866]

Fri Jun 4 14:00:00 2010
- remove the devel packages from baselibs.conf, not convinced of
their usefulness

Sat Apr 24 14:00:00 2010
- buildrequire pkg-config to fix provides

Thu Feb 25 13:00:00 2010
- updated to 1.2.43 (fixes [bnc#585403]):

* Removed \"#define PNG_NO_ERROR_NUMBERS\" that was inadvertently added
to pngconf.h in version 1.2.41.

* Removed leftover \"-DPNG_CONFIGURE_LIBPNG\" from scripts/makefile.darwin
and contrib/pngminim/

* Relocated png_do_chop() to its original position in pngrtran.c; the
change in version 1.2.41beta08 caused transparency to be handled wrong
in some 16-bit datastreams (Yusaku Sugai).

* Renamed back to and revised CMakeLists.txt
(revising changes made in 1.2.41)

in pngset.c to be consistent with other changes in version 1.2.38.

* Avoid deprecated references to png_ptr-io_ptr and png_ptr->error_ptr
in pngtest.c

Mon Dec 14 13:00:00 2009
- add baselibs.conf as a source

Mon Dec 7 13:00:00 2009
- updated to 1.2.41:
contains numerous cleanups, some new compile-time warnings about
direct struct access (define PNG_NO_PEDANTIC_WARNINGS to enable),
a new xcode build project, and a minor performance improvement
(avoid building 16-bit gamma tables when not needed)

Tue Nov 24 13:00:00 2009
- updated to 1.2.40:
Removed an extra png_debug() recently added to png_write_find_filter().
Fixed incorrect #ifdef in pngset.c regarding unknown chunk support.
Various bugfixes and improvements to CMakeLists.txt (Philip Lowman)

Tue Nov 3 13:00:00 2009
- updated patches to apply with fuzz=0

Thu Aug 13 14:00:00 2009
- updated to 1.2.39:

* Added a prototype for png_64bit_product() in png.c

* Avoid a possible NULL dereference in debug build,
in png_set_text_2()

* Relocated new png_64_bit_product() prototype into png.h

* Replaced
*.tar.lzma with
*.txz in distribution.

* Reject attempt to write iCCP chunk with negative embedded
profile length.

Mon Jul 20 14:00:00 2009
- updated to 1.2.38:

* Revised libpng
*.txt and libpng.3 to mention calling png_set_IHDR()
multiple times and to specify the sample order in the tRNS chunk,
because the ISO PNG specification has a typo in the tRNS table.

PNG_HANDLE_AS_UNKNOWN_SUPPORTED, to make the png_set_keep mechanism
available for ignoring known chunks even when not saving unknown chunks.

* Adopted preference for consistent use of \"#ifdef\" and \"#ifndef\" versus
\"#if defined()\" and \"if !defined()\" where possible.

pngconf.h, and moved the various unknown chunk macro definitions

Thu Jun 4 14:00:00 2009
- updated to 1.2.37:

* fixed bug with new png_memset() of the big_row_buffer

Tue May 12 14:00:00 2009
- updated to 1.2.36 (see CHANGES)