An integer overflow was discovered in the way freetype processes malformed PCF
files. It seems that Xorg also contains the same PCF processing code as
freetype, there it too is vulnerable this issue.
We initally described this issue for freetype in bug 190593.
The upstream bug is here:
The upstream patch is attachment 134155 [details]
Created attachment 134276 [details]
Demo font file
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.