[Buildroot] [PATCH] freetype: add upstream security fixes for CVE-2017-8105 and CVE-2017-8287
Peter Korsgaard
peter at korsgaard.com
Mon May 1 07:20:32 UTC 2017
>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:
> Add upstream post-2.7.1 commits (except for ChangeLog modifications) fixing
> the following security issues:
> CVE-2017-8105 - FreeType 2 before 2017-03-24 has an out-of-bounds write
> caused by a heap-based buffer overflow related to the
> t1_decoder_parse_charstrings function in psaux/t1decode.c.
> CVE-2017-8287 - FreeType 2 before 2017-03-26 has an out-of-bounds write
> caused by a heap-based buffer overflow related to the
> t1_builder_close_contour function in psaux/psobjs.c.
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
Committed to 2017.02.x, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list