[Png-mng-security] vulnerability in png_decompress_chunk()

Bob Friesenhahn bfriesen at simple.dallas.tx.us
Fri Jan 29 21:21:13 UTC 2010


On Fri, 29 Jan 2010, Glenn Randers-Pehrson wrote:
> 
> It has been said that even just *adding* a new exported function breaks
> ABI compatibility, but I'm not sure that I really believe that.

It certainly can.  For example, Cygwin only knows the major version 
('current') of the library and it is embedded in the library name.  If 
the library name was not changed, then it would probably work.

Bob
--
Bob Friesenhahn
bfriesen at simple.dallas.tx.us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/



More information about the png-mng-security-archive mailing list