author Dana Keeler <>
Fri, 27 Jan 2023 04:07:10 +0000
changeset 650755 f75c73066b887c2379158c73c994b5ef95460238
parent 643327 a5be9935747857b3e18f4ca2bdea4e94c7bb97b2
permissions -rw-r--r--
Bug 1811633 - use updated, vendored version of PKI.js, remove old version r=Gijs This also converts certDecoder.jsm to an ES module (as certDecoder.mjs) and updates all uses of it. Differential Revision:

libpng 1.6.39 - November 20, 2022

This is a public release of libpng, intended for use in production code.

Files available for download

Source files with LF line endings (for Unix/Linux):

 * libpng-1.6.39.tar.xz (LZMA-compressed, recommended)
 * libpng-1.6.39.tar.gz

Source files with CRLF line endings (for Windows):

 * lpng1639.7z (LZMA-compressed, recommended)

Other information:


Changes from version 1.6.38 to version 1.6.39

 * Changed the error handler of oversized chunks (i.e. larger than
   PNG_USER_CHUNK_MALLOC_MAX) from png_chunk_error to png_benign_error.
 * Fixed a buffer overflow error in contrib/tools/pngfix.
 * Fixed a memory leak (CVE-2019-6129) in contrib/tools/pngcp.
 * Disabled the ARM Neon optimizations by default in the CMake file,
   following the default behavior of the configure script.
 * Allowed to work with the trunk version of autoconf.
 * Removed the support for "install" targets from the legacy makefiles;
   removed the obsolete makefile.cegcc.
 * Cleaned up the code and updated the internal documentation.

Send comments/corrections/commendations to png-mng-implement at
Subscription is required; visit
to subscribe.