A NULL pointer dereference vulnerability was found in cairo. A maliciously crafted font file could cause the application to crash. Upstream bug: https://bugs.freedesktop.org/show_bug.cgi?id=100763 References: http://seclists.org/oss-sec/2017/q2/151
Created cairo tracking bugs for this issue: Affects: fedora-all [bug 1447973] Created mingw-cairo tracking bugs for this issue: Affects: epel-all [bug 1447972]
Created mingw-cairo tracking bugs for this issue: Affects: fedora-all [bug 1447976]
I have made the reproducer public: https://bugs.freedesktop.org/show_bug.cgi?id=100763