{"bugs":[{"bugid":759013,"firstseen":"2025-07-11T02:48:40.189262","severity":"minor","status":"IN_PROGRESS","summary":"<media-gfx\/pngcheck-3.0.2: Multiple vulnerabilities (CVE-2020-27818)"},{"bugid":866233,"firstseen":"2025-07-11T02:48:40.189262","severity":"minor","status":"IN_PROGRESS","summary":"<media-gfx\/pngcheck-3.0.3: global buffer overflow"}],"categories":[{"categoryid":354,"name":"media-gfx","summary":"The media-gfx category contains graphics-related packages."},{"categoryid":396,"name":"virtual","summary":"The virtual category contains packages which satisfy virtual dependencies."}],"changelog":[{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"f1edc6bdd66407c995842e4c229ee0089fd7fd8e","committime":"2026-03-11T16:15:47","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Signed-off-by: Sam James <sam@gentoo.org>","commitid":"42dd064b137c857009e67e295b758b8ac4e2cd36","committime":"2026-03-11T15:57:51","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: add 4.0.1, drop 4.0.0"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"e09be1650bf1ab608446c80c6ac2835c083e91fe","committime":"2025-11-04T10:20:41","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"mgorny@gentoo.org","authorname":"Michał Górny","body":"Done via:\n\n```\ngit grep -l 'virtual\/zlib\"' | xargs sed -i -e 's@virtual\/zlib\"@virtual\/zlib:=\"@'\n```\n\nSigned-off-by: Michał Górny <mgorny@gentoo.org>","commitid":"3f9689daa18058fa4adc944100fa1f95bfbaa5b4","committime":"2025-11-04T10:07:52","packageid":47672,"repoid":1,"summary":"*\/*: Use := on virtual\/zlib deps, part 6"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"264e3c99fc745646475409ea475d643ce2dc7e4b","committime":"2025-11-04T08:20:44","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"mgorny@gentoo.org","authorname":"Michał Górny","body":"Update done using:\n\n```\ngit grep -l sys-libs\/zlib media-* | xargs sed -i -e s@sys-libs\/zlib@virtual\/zlib@g\ngit diff --name-only | xargs copybump\ngit diff --name-only | xargs grep -l PYTHON_COMPAT | xargs gpy-impl -@dead\npkgcheck scan --commits -c SourcingCheck,VisibilityCheck --exit error\n```\n\nSigned-off-by: Michał Górny <mgorny@gentoo.org>","commitid":"93b8ec20c54c02c297553c15f5047b2077ba5318","committime":"2025-11-04T08:10:32","packageid":47672,"repoid":1,"summary":"media-*\/*: update for virtual\/zlib"},{"authoremail":"jy6x2b32pie9@yahoo.com","authorname":"NHOrus","body":"PNG Group released new version of PNG specification, it includes\nHDR and APNG chunks. Accompanying process of designing that spec,\nupstream pngcheck changed maintainer and was updated to verify\nnew chunks.\nNew version also added cmake as main building system, simplifying\nebuild significantly.\n\nCloses: https:\/\/bugs.gentoo.org\/959630\nSigned-off-by: NHOrus <jy6x2b32pie9@yahoo.com>\nPart-of: https:\/\/github.com\/gentoo\/gentoo\/pull\/42899\nCloses: https:\/\/github.com\/gentoo\/gentoo\/pull\/42899\nSigned-off-by: Sam James <sam@gentoo.org>","commitid":"b15de83cf0dd1e4e8bffdc33adf22bde60c50ae1","committime":"2025-07-06T08:28:38","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: add 4.0.0"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"2d4f9ad1d83a8192fddb6746669bc83bb4a67e83","committime":"2024-09-13T08:06:19","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"arkamar@gentoo.org","authorname":"Petr Vaněk","body":"Bug: https:\/\/bugs.gentoo.org\/866233\nSigned-off-by: Petr Vaněk <arkamar@gentoo.org>","commitid":"41390b62f0ee323634f2cca6b019543de1cbf0c3","committime":"2024-09-13T07:57:19","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: drop 3.0.2"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"e817756739654c06c8a96e8fb68a3da1ba3af055","committime":"2024-04-30T18:48:55","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"watermanpaint@posteo.net","authorname":"Lucio Sauer","body":"bump copyright of touched ebuilds to 2024\n\nSigned-off-by: Lucio Sauer <watermanpaint@posteo.net>\nSigned-off-by: Michał Górny <mgorny@gentoo.org>","commitid":"794061a3298b5716db015defa7b3e2c583b73980","committime":"2024-04-12T10:47:52","packageid":47672,"repoid":1,"summary":"*\/*: inline mirror:\/\/sourceforge"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"8daef4a25345d32fef4e6abad00a4fda07390d31","committime":"2023-02-24T17:46:53","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Signed-off-by: Sam James <sam@gentoo.org>","commitid":"48a5a298387e6dd48a707debf66795253524cb27","committime":"2023-02-24T17:38:15","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: Stabilize 3.0.3 x86, #896306"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"b463d077480f863104f25ea65c7392d5db2b7d23","committime":"2023-02-24T17:01:56","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Signed-off-by: Sam James <sam@gentoo.org>","commitid":"8996c4d90b9a8f56165182138ebb04fbb810aba4","committime":"2023-02-24T16:55:42","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: Stabilize 3.0.3 amd64, #896306"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"c72360185aa18edb5566b07d611baedcc0396be4","committime":"2022-12-16T07:31:58","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Bug: https:\/\/bugs.gentoo.org\/866233\nSigned-off-by: Sam James <sam@gentoo.org>","commitid":"34564839cadebb24c14385ce59055d7c5ead97c2","committime":"2022-12-16T07:16:34","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: add 3.0.3"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"187aa4af367e11312a99a3bb5c93541acad14c05","committime":"2021-02-22T03:52:13","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"ajak@gentoo.org","authorname":"John Helmert III","body":"Bug: https:\/\/bugs.gentoo.org\/759013\nPackage-Manager: Portage-3.0.14, Repoman-3.0.2\nSigned-off-by: John Helmert III <ajak@gentoo.org>","commitid":"3db3577dba537c0ddde48f86fdce2d523acf14c4","committime":"2021-02-22T03:10:00","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: security cleanup (drop <3.0.2)"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"49356f4a95cdf3a2436408f5806b9a04e78792dd","committime":"2021-02-09T12:18:00","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Signed-off-by: Sam James <sam@gentoo.org>","commitid":"5a22a9392fee1d97610309acfed21f8445de3513","committime":"2021-02-09T09:47:12","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: Stabilize 3.0.2 amd64, #759013"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"09be802a9e759592a9cdcb726a9bdedb2cfe2805","committime":"2021-02-08T19:17:30","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Signed-off-by: Sam James <sam@gentoo.org>","commitid":"71225fbbfe0a3b6687f2ea653d878d1dd45ebf6a","committime":"2021-02-08T17:26:24","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: Stabilize 3.0.2 x86, #759013"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"49461d59058e8dae0d4bc61074dae424c6c54cb4","committime":"2021-02-02T00:17:24","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"sam@gentoo.org","authorname":"Sam James","body":"Bug: https:\/\/bugs.gentoo.org\/759013\nPackage-Manager: Portage-3.0.14, Repoman-3.0.2\nSigned-off-by: Sam James <sam@gentoo.org>","commitid":"531a61e9d885c091ea7ab0596f9367e2f40a15af","committime":"2021-02-01T19:23:52","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: (security) bump to 3.0.2"},{"authoremail":"repomirrorci@gentoo.org","authorname":"Repository mirror & CI","commitid":"ea092408de997c0731a05d439dd8e1ec624981c6","committime":"2018-10-27T16:04:09","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"asturm@gentoo.org","authorname":"Andreas Sturmlechner","body":"Closes: https:\/\/bugs.gentoo.org\/666296\nThanks-to: Michael Mair-Keimberger <m.mairkeimberger@gmail.com>\nSigned-off-by: Andreas Sturmlechner <asturm@gentoo.org>","commitid":"54c2580a88455cca5fdfed46508513cc2d1977bd","committime":"2018-10-27T15:02:11","packageid":47672,"repoid":1,"summary":"media-gfx\/pngcheck: EAPI7, drop superfluous || die"},{"authoremail":"repo-qa-checks@gentoo.org","authorname":"Repository QA checks","commitid":"25093d6359f778b8d1052f66ba9e26fc29ded21a","committime":"2017-02-28T20:35:29","packageid":47672,"repoid":1,"summary":"Merge updates from master"},{"authoremail":"robbat2@gentoo.org","authorname":"Robin H. Johnson","body":"Signed-off-by: Robin H. Johnson <robbat2@gentoo.org>","commitid":"61b861acd7b49083dab687e133f30f3331cb7480","committime":"2017-02-28T19:47:27","packageid":47672,"repoid":1,"summary":"Drop $Id$ per council decision in bug #611234."},{"authoremail":"repo-qa-checks@gentoo.org","authorname":"Repository QA checks","commitid":"945f0d2a26da4f944fd06ad6a874f69d37ce1e06","committime":"2015-08-09T09:26:46","packageid":47672,"repoid":1,"summary":"2015-08-09 09:26:21 UTC"},{"authoremail":"robbat2@gentoo.org","authorname":"Robin H. Johnson","body":"This commit represents a new era for Gentoo:\nStoring the gentoo-x86 tree in Git, as converted from CVS.\n\nThis commit is the start of the NEW history.\nAny historical data is intended to be grafted onto this point.\n\nCreation process:\n1. Take final CVS checkout snapshot\n2. Remove ALL ChangeLog* files\n3. Transform all Manifests to thin\n4. Remove empty Manifests\n5. Convert all stale $Header$\/$Id$ CVS keywords to non-expanded Git $Id$\n5.1. Do not touch files with -kb\/-ko keyword flags.\n\nSigned-off-by: Robin H. Johnson <robbat2@gentoo.org>\nX-Thanks: Alec Warner <antarus@gentoo.org> - did the GSoC 2006 migration tests\nX-Thanks: Robin H. Johnson <robbat2@gentoo.org> - infra guy, herding this project\nX-Thanks: Nguyen Thai Ngoc Duy <pclouds@gentoo.org> - Former Gentoo developer, wrote Git features for the migration\nX-Thanks: Brian Harring <ferringb@gentoo.org> - wrote much python to improve cvs2svn\nX-Thanks: Rich Freeman <rich0@gentoo.org> - validation scripts\nX-Thanks: Patrick Lauer <patrick@gentoo.org> - Gentoo dev, running new 2014 work in migration\nX-Thanks: Michał Górny <mgorny@gentoo.org> - scripts, QA, nagging\nX-Thanks: All of other Gentoo developers - many ideas and lots of paint on the bikeshed","commitid":"56bd759df1d0c750a065b8c845e93d5dfa6b549d","committime":"2015-08-08T20:49:04","packageid":47672,"repoid":1,"summary":"proj\/gentoo: Initial commit"},{"authoremail":"repo-qa-checks@gentoo.org","authorname":"Repository QA checks","commitid":"a637bd65b7fef8e2be4e7fc6e9097479372e0e2e","committime":"2015-06-19T16:38:33","packageid":47672,"repoid":1,"summary":"2015-06-19 16:35:30 UTC"}],"dependencies":[{"block":false,"categoryid":396,"description":"Virtual for libz.so providers","ebuildids":[772280,892516],"firstseen":"2025-11-04T07:31:41.418357","name":"zlib","packageid":78605}],"depending":[],"ebuilds":[{"archs":["~amd64","~x86"],"ebuildid":892516,"firstseen":"2026-03-11T16:24:32.179690","license":"HPND GPL-2+","moddate":"2026-03-28T18:04:21","packageid":47672,"repoid":1,"slot":"0","uses":[],"version":"4.0.1"},{"archs":["amd64","x86"],"ebuildid":772280,"firstseen":"2022-12-16T07:46:15.269476","license":"HPND GPL-2+","moddate":"2026-03-22T20:20:56","packageid":47672,"repoid":1,"slot":"0","uses":[],"version":"3.0.3"}],"masks":[],"package":{"categoryid":354,"description":"Verifies the integrity of PNG, JNG, and MNG files with internal checksums","firstseen":"2010-05-04T00:54:45.661860","maintainer":"graphics@gentoo.org","maintainername":"Gentoo Graphics Project","name":"pngcheck","packageid":47672},"rdependencies":[{"block":false,"categoryid":396,"description":"Virtual for libz.so providers","ebuildids":[772280,892516],"firstseen":"2025-11-04T07:31:41.418357","name":"zlib","packageid":78605}],"repos":[{"branch":"master","lastcommit":"f87ce2b74421571078063820dc1065e7089c9fa7","name":"gentoo","path":"\/usr\/portage","repoid":1,"upstream":"origin"}],"tracked":false,"urls":["https:\/\/github.com\/pnggroup\/pngcheck","https:\/\/www.libpng.org\/pub\/png\/apps\/pngcheck.html"],"uses":[]}