An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
| Software | From | Fixed in |
|---|---|---|
| freetype / freetype | - | 2.9.x |
| canonical / ubuntu_linux | 17.10 | 17.10.x |