An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file (CVE-2018-6942).
{ "section": "tainted" }
"https://advisories.mageia.org/MGASA-2018-0140.json"
{ "section": "core" }