[Buildroot] [PATCH] freetype: add upstream security fixes for CVE-2017-8105 and CVE-2017-8287

Peter Korsgaard peter at korsgaard.com
Mon May 1 07:20:32 UTC 2017


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Add upstream post-2.7.1 commits (except for ChangeLog modifications) fixing
 > the following security issues:

 > CVE-2017-8105 - FreeType 2 before 2017-03-24 has an out-of-bounds write
 > caused by a heap-based buffer overflow related to the
 > t1_decoder_parse_charstrings function in psaux/t1decode.c.

 > CVE-2017-8287 - FreeType 2 before 2017-03-26 has an out-of-bounds write
 > caused by a heap-based buffer overflow related to the
 > t1_builder_close_contour function in psaux/psobjs.c.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2017.02.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list