From c334bdf793c04920b5eb6c1c7fd5a022cd02b8e9 Mon Sep 17 00:00:00 2001 From: Glenn Randers-Pehrson Date: Sun, 3 Sep 2017 09:33:23 -0500 Subject: [libpng14] Mention CVE-2017-12652 in CHANGES. --- CHANGES | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGES b/CHANGES index 19eb7b975..9572f5233 100644 --- a/CHANGES +++ b/CHANGES @@ -3044,6 +3044,7 @@ version 1.4.20 [December 29, 2016] and patch by Patrick Keshishian, CVE-2016-10087). version 1.4.21beta [August 9, 2017] + Added png_check_chunk_length() function (Fixes CVE-2017-12652). Moved chunk-name and chunk-length checks into PNG_EXTERN private png_check_chunk_name() and png_check_chunk_length() functions (Suggested by Max Stepin). -- cgit v1.2.1