FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c. Bug report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=289
Created freetype tracking bugs for this issue: Affects: fedora-all [bug 1444917] Created mingw-freetype tracking bugs for this issue: Affects: epel-7 [bug 1444915] Affects: fedora-all [bug 1444916]
I can not reproduce this one too with our freetype versions.
This issue arises due to the following commit: http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=3bd79cc257499f1850a1bace21f3ae371e3b40f0 Which has not been backported to version of freetype shipped with Red Hat Enterprise Linux and Fedora, hence these versions are not affected. Upstream versions may also not be affected, because this was a very short lived regression.