The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before
2.4.2 does not properly validate certain position values, which allows
remote attackers to cause a denial of service (application crash) or
possibly execute arbitrary code via a crafted font file.
Updated: 2016-01-26 17:36:47 UTC (commit 10507)