FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1builderclose_contour function in psaux/psobjs.c.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "freetype2-demos-dbgsym": "2.5.2-1ubuntu2.8", "libfreetype6-udeb": "2.5.2-1ubuntu2.8", "libfreetype6-dbgsym": "2.5.2-1ubuntu2.8", "libfreetype6-dev": "2.5.2-1ubuntu2.8", "freetype2-demos": "2.5.2-1ubuntu2.8", "libfreetype6-udeb-dbgsym": "2.5.2-1ubuntu2.8", "libfreetype6": "2.5.2-1ubuntu2.8" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "freetype2-demos-dbgsym": "2.6.1-0.1ubuntu2.3", "libfreetype6-udeb": "2.6.1-0.1ubuntu2.3", "libfreetype6-dbgsym": "2.6.1-0.1ubuntu2.3", "libfreetype6-dev": "2.6.1-0.1ubuntu2.3", "freetype2-demos": "2.6.1-0.1ubuntu2.3", "libfreetype6-udeb-dbgsym": "2.6.1-0.1ubuntu2.3", "libfreetype6": "2.6.1-0.1ubuntu2.3" } ] }