FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TTGetMMVar function in truetype/ttgxvar.c and the sfntinit_face function in sfnt/sfobjs.c.
{ "source": "REFERENCES" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7857.json"
{ "cpe": "cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*", "source": "CPE_RANGE", "extracted_events": [ { "introduced": "2.7" }, { "fixed": "2.8" } ] }