Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c (CVE-2017-12067).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0280.json"