FreeType before 2.6.1 has a heap-based buffer over-read in T1GetPrivate_Dict in type1/t1parse.c.
{ "urgency": "not yet assigned" }