An integer overflow in the ttvarloaditemvariation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.
{
"binaries": [
{
"binary_version": "2.13.2+dfsg-1ubuntu0.1",
"binary_name": "freetype2-demos"
},
{
"binary_version": "2.13.2+dfsg-1ubuntu0.1",
"binary_name": "libfreetype-dev"
},
{
"binary_version": "2.13.2+dfsg-1ubuntu0.1",
"binary_name": "libfreetype6"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "2.13.3+dfsg-1ubuntu0.1",
"binary_name": "freetype2-demos"
},
{
"binary_version": "2.13.3+dfsg-1ubuntu0.1",
"binary_name": "libfreetype-dev"
},
{
"binary_version": "2.13.3+dfsg-1ubuntu0.1",
"binary_name": "libfreetype6"
}
],
"availability": "No subscription required"
}