Update Info

openSUSE-2023-383


Security update for optipng


Type: security
Severity: important
Issued: 2023-11-29
Description:
This update for optipng fixes the following issues:

optipng was updated to 0.7.8:

* Upgraded libpng to version 1.6.40.
* Upgraded zlib to version 1.3-optipng.
* Upgraded cexcept to version 2.0.2-optipng.

* Fixed a global-buffer-overflow vulnerability in the GIF reader (boo#1215937 CVE-2023-43907).
* Fixed a stack-print-after-scope defect in the error handler.
* Fixed an assertion failure in the image reduction module.
* Fixed the command-line wildargs expansion in the Windows port.
* Raised the minimum required libpng version from 1.2.9 to 1.6.35.
* Raised the minimum required zlib version from 1.2.1 to 1.2.8.
* Refactored the structured exception handling.


              

Packages


  • optipng-0.7.8-bp155.5.5.1