If the Postscript stream contains a broken number-with-base (e.g. "8#garbage") the cursor doesn't advance and parse_encoding enters an infinite loop. Upstream patch: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=df14e6c0b9592cbb24d5381dfc6106b14f915e75 CVE request: http://seclists.org/oss-sec/2015/q3/537
Created freetype tracking bugs for this issue: Affects: fedora-all [bug 1262381]
Created mingw-freetype tracking bugs for this issue: Affects: fedora-all [bug 1262380] Affects: epel-7 [bug 1262382]
It seems to me that this is already fixed in all maintained versions of Fedora. Check it please.
Upstream freetype git suggests that this issue was addressed in freetype-2.5.3. Therefore this issue is already fixed in all the maintained versions of Fedora.