Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
{ "urgency": "unimportant" }