Jump to content

getchagetcha

Newbies
  • Posts

    1
  • Joined

  • Last visited

Posts posted by getchagetcha

  1. Perhaps it should be updated to OptiPNG 0.6.5, as versions 0.6.2 (& below) have unpatched security vulnerabilities:

    • All past OptiPNG versions, up to and including version 0.6.2, are known to be vulnerable to use-after-free attacks, due to a bug in the GIF image reader. (Many thanks to Roy Tam for the report, and to Bryan McQuade for the fix.)
    • OptiPNG versions 0.6 and 0.6.1 are known to be vulnerable to array-overflow attacks, due to a bug in the BMP image reader. (Many thanks to an anonymous user for the report.)

    0.6.5 was release 2011-01-24.

    It looks like support for this plugin is dead. The OptiPNG project itself does provide Win32 builds (no Win64, sadly--would probably be a lot faster). I'm using their pseudo-nightly build (from the Mercurial repo, presumably more recent code than 0.7.1), and it appears to work correctly as a drop-in replacement for the included optipng.exe. 0.7.1 fixes not just security flaws, but an actual image corruption bug for grayscale images.

    It would be really nice to see OptiPNG included (stand-alone download if necessary) as an official plugin for PDN, preferably in 64-bit native. libjpeg-turbo wouldn't hurt, either...

×
×
  • Create New...