MESSAGE
DATE | 2021-04-16 |
FROM | Derrick McKee
|
SUBJECT | Subject: [Hangout - NYLXS] [png-mng-implement] Missing patch for
|
From hangout-bounces-at-nylxs.com Sat Apr 17 09:49:51 2021 Return-Path: X-Original-To: archive-at-mrbrklyn.com Delivered-To: archive-at-mrbrklyn.com Received: from www2.mrbrklyn.com (www2.mrbrklyn.com [96.57.23.82]) by mrbrklyn.com (Postfix) with ESMTP id 3632E163FB5; Sat, 17 Apr 2021 09:49:51 -0400 (EDT) X-Original-To: hangout-at-www2.mrbrklyn.com Delivered-To: hangout-at-www2.mrbrklyn.com Received: by mrbrklyn.com (Postfix, from userid 1000) id BF594163FB0; Sat, 17 Apr 2021 09:49:48 -0400 (EDT) Resent-From: Ruben Safir Resent-Date: Sat, 17 Apr 2021 09:49:48 -0400 Resent-Message-ID: <20210417134948.GA9571-at-www2.mrbrklyn.com> Resent-To: hangout-at-mrbrklyn.com X-Original-To: ruben-at-mrbrklyn.com Delivered-To: ruben-at-mrbrklyn.com Received: from lists.sourceforge.net (lists.sourceforge.net [216.105.38.7]) by mrbrklyn.com (Postfix) with ESMTP id 08A37163FAC for ; Fri, 16 Apr 2021 12:03:29 -0400 (EDT) Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from ) id 1lXQvh-0000Vj-4G; Fri, 16 Apr 2021 16:02:49 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lXQvf-0000Vc-Mb for png-mng-implement-at-lists.sourceforge.net; Fri, 16 Apr 2021 16:02:47 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:To:Subject:Message-ID:Date:From: MIME-Version:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=JMO3zUtm1HqX0RrOC2/8SdCjcNowb+8uN3uDWnpf4BI=; b=Acd7gHGaCsb+T1w4p6ROv0vS5p ASIFh7PKlRomTeAb/meXZ5GPXY78x/4K0JgOgbTC3Xb1Sp/61I3Tz9w3ytCklsbAr+hs9kE90IrZL woKdqKvSA+kYXVU4YwXQL7o7auRpot8w1F22MY4mhzbbTXj6i/wV8OugGGKrrmKEooo4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:To:Subject:Message-ID:Date:From:MIME-Version:Sender:Reply-To :Cc:Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=JMO3zUtm1HqX0RrOC2/8SdCjcNowb+8uN3uDWnpf4BI=; b=k 6i8VglfMcWGBzoE32zZKQHncB9Qxzfj3CkVjKoNGBgnO42q0FnSsCJQYU0XQpG2rDPN6M3lvBAG3c KHHUW5f4VbAHyldb2hAP6k4ONlkzZJnAak5wPJi4AA61k8wM1YaA5Q9n07fbv+8Y0ozXQ4Ncv3w33 vRfCCculjaNfzmr8=; Received: from mail-qv1-f46.google.com ([209.85.219.46]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.92.3) id 1lXQvb-0003bW-7r for png-mng-implement-at-lists.sourceforge.net; Fri, 16 Apr 2021 16:02:48 +0000 Received: by mail-qv1-f46.google.com with SMTP id er3so5161266qvb.6 for ; Fri, 16 Apr 2021 09:02:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=JMO3zUtm1HqX0RrOC2/8SdCjcNowb+8uN3uDWnpf4BI=; b=Qge2lyS9eCztqLL6Vr4TtYIDJCC4uSZ0FgWUmXLomyUuNYGQOQmsOIyFJ0J1AP5hTB 2hPDgyZryg/L82/GOkFyP0lDYhAiIpsmlYFEDdI+iTs6gpTczcUfrsnkmiR/ba2xM+Yi fM4XrE5xoCfkz0e+mW3WkTf9PXPAQSR3LZgnsi26WTNk++vQMeFvVlx2TJeTSuH619o2 8arMX31tG1VCQvnD2sp3qV0WB3siMbMOa1rbruoVSI9VnFobSc/PioX9Kqmp+FJ8QIUg ACf9XT/CKDmYVGDtVgaw29McFHauuuTcfKesecsr09vdQP4eBL05s6BzhvHKieqfg/w5 O+Jg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=JMO3zUtm1HqX0RrOC2/8SdCjcNowb+8uN3uDWnpf4BI=; b=hp4Kr5czA0ohB2AKlS5/pPHNpApZ8b1DloPJxdhDa56BJt2GNStNpS4gZS1iIOci3v 5VsiZ6c5bTkewKZ/Ol9UVsZwqcS3ofJilyLhSBjzLtAlR6JbC0wGO7Z1e3ksCbrKUxTs Fh79KtewiuL3RhVXl3oHELdJAx1i0TTaY3m0rCYNPuP0TrKDyIsWchlXGVhYqTj5/jpx f6RzkgyFNNdgPdOgJUfnTOEOqK9lz3Sa6WVvG8NsYnG/xfFzgcdULxianhwG+JCXx9IS R8WW4ZbYhb2bzxTJHupeo4hzLUZc1+yTFGr8kXoVnxjV8jq5rJ+rAhOHVS5ZuLJpu23S pMVw== X-Gm-Message-State: AOAM533/9IIAGWkfvqOcAGc0cWEPEPKk5xKihQxulSwkh1rlE06q9TKV OtP24UK7VcUeTffC+/swxhmOjyHZeRBNiXl4kGu1z3n7bVg= X-Google-Smtp-Source: ABdhPJxV1n4TJov1+Mm9gD6QS4mez0z7VXreP3aPCG2Mi8DMNs9AEYnnvv5qL4FmMtvRNK35pTVc/BvfClWNnOBQ25g= X-Received: by 2002:a0c:f04a:: with SMTP id b10mr9045552qvl.59.1618588957152; Fri, 16 Apr 2021 09:02:37 -0700 (PDT) MIME-Version: 1.0 From: Derrick McKee Date: Fri, 16 Apr 2021 12:02:26 -0400 Message-ID: To: png-mng-implement-at-lists.sourceforge.net X-Spam-Score: -0.1 (/) X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [209.85.219.46 listed in list.dnswl.org] 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (derrick.mckee[at]gmail.com) -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [209.85.219.46 listed in wl.mailspike.net] X-Headers-End: 1lXQvb-0003bW-7r X-BeenThere: png-mng-implement-at-lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list Subject: [Hangout - NYLXS] [png-mng-implement] Missing patch for CVE-2017-12652 X-BeenThere: hangout-at-nylxs.com List-Id: NYLXS Tech Talk and Politics List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: PNG/MNG implementation discussion list Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: hangout-bounces-at-nylxs.com Sender: "Hangout"
Hi,
I see that commit 347538efbdc21b8df684ebd92d37400b3ce85d55 includes a fix for CVE-2017-12652 in pngpread.c. However, that fix appears to be missing starting in tag v1.6.32beta10, and no longer appears in the source. Can anyone explain what happened? Thanks.
-- Derrick McKee Phone: (703) 957-9362 Email: derrick.mckee-at-gmail.com
_______________________________________________ png-mng-implement mailing list png-mng-implement-at-lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/png-mng-implement _______________________________________________ Hangout mailing list Hangout-at-nylxs.com http://lists.mrbrklyn.com/mailman/listinfo/hangout
|
|