FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
| Software | From | Fixed in |
|---|---|---|
| freetype / freetype | - | 2.7.1 |
| debian / debian_linux | 8.0 | 8.0.x |