FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.
{ "binaries": [ { "binary_name": "freetype2-demos", "binary_version": "2.5.2-1ubuntu2.8+esm2" }, { "binary_name": "libfreetype6", "binary_version": "2.5.2-1ubuntu2.8+esm2" }, { "binary_name": "libfreetype6-dev", "binary_version": "2.5.2-1ubuntu2.8+esm2" } ] }
{ "binaries": [ { "binary_name": "freetype2-demos", "binary_version": "2.6.1-0.1ubuntu2.5+esm2" }, { "binary_name": "libfreetype6", "binary_version": "2.6.1-0.1ubuntu2.5+esm2" }, { "binary_name": "libfreetype6-dev", "binary_version": "2.6.1-0.1ubuntu2.5+esm2" } ] }
{ "binaries": [ { "binary_name": "freetype2-demos", "binary_version": "2.8.1-2ubuntu2.2+esm1" }, { "binary_name": "libfreetype6", "binary_version": "2.8.1-2ubuntu2.2+esm1" }, { "binary_name": "libfreetype6-dev", "binary_version": "2.8.1-2ubuntu2.2+esm1" } ] }