Closed Bug 1224244 Opened 4 years ago Closed 4 years ago

Update in-tree libpng to version 1.6.19

Categories

(Core :: ImageLib, defect)

defect
Not set

Tracking

()

RESOLVED FIXED
mozilla45
Tracking Status
firefox45 --- fixed

People

(Reporter: glennrp+bmo, Assigned: glennrp+bmo)

References

Details

Attachments

(1 file, 3 obsolete files)

libpng-1.6.19 has been released.  Mozilla is not vulnerable to the security issues that it fixes, when using either the in-tree libpng or the system libpng.
Assignee: nobody → glennrp+bmo
Status: NEW → ASSIGNED
Depends on: 1186977
try?
Flags: needinfo?(ryanvm)
Never mind try right now, an ARM supporting file has been moved.
Flags: needinfo?(ryanvm)
Attachment #8686958 - Attachment is obsolete: true
Updated configure.in with new minimum libpng version
Attachment #8686970 - Attachment is obsolete: true
Should be OK for a try run now.
Flags: needinfo?(ryanvm)
Comment on attachment 8687320 [details] [diff] [review]
V02 update embedded libpng to version 1.6.19

Try run was 100% green; looks good to go.  R?
Attachment #8687320 - Flags: review?(seth)
libpng-1.6.20 will most likely be out next week, December 3, 2015, so we might as well skip 1.6.19.  Like libpng-1.6.19, libpng-1.6.20 fixes vulnerabilities that don't affect mozilla, whether using the embedded libpng or the system libpng.  Cancelling "r?".
Summary: Update in-tree libpng to version 1.6.19 → Update in-tree libpng to version 1.6.20
Attachment #8687320 - Flags: review?(seth) → review-
Comment on attachment 8687320 [details] [diff] [review]
V02 update embedded libpng to version 1.6.19

Review of attachment 8687320 [details] [diff] [review]:
-----------------------------------------------------------------

Looks good! I didn't review the changes to libpng itself, obviously, just the Gecko-specific changes (and the CHANGES file, just to familiarize myself with what had changed).
Attachment #8687320 - Flags: review- → review+
Keywords: checkin-needed
Rebased configure.in
Attachment #8687320 - Attachment is obsolete: true
Seth, please transfer r+ from v02 to v03 patch.  The only difference is the rebase of configure.in.
Flags: needinfo?(seth)
(In reply to Glenn Randers-Pehrson from comment #11)
> Seth, please transfer r+ from v02 to v03 patch.  The only difference is the
> rebase of configure.in.

i guess that means that the r+ is just carryover to the last rebased patch. so checkin this in, seth correct me if i'm wrong
Thanks, that's what I intended.  I'll open a new bug for libpng-1.6.20.
Summary: Update in-tree libpng to version 1.6.20 → Update in-tree libpng to version 1.6.19
https://hg.mozilla.org/mozilla-central/rev/9257f9006397
Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla45
Flags: needinfo?(seth)
Blocks: 1230757
You need to log in before you can comment on or make changes to this bug.