See Savannah bug #30975. * src/cff/cffload.c (cff_index_access_element): `off2', the offset to the next element is truncated at the end of the stream to prevent invalid I/O. As `off1', the offset to the requested element has been checked by FT_STREAM_SEEK(), `off2' should be checked similarly.dbgmem-more-limiters
parent
d2d843a01c
commit
73aa20ca1d
2 changed files with 22 additions and 0 deletions
Loading…
Reference in new issue