In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-30T12:36:19

Updated: 2019-10-09T19:06:32

Reserved: 2019-07-30T00:00:00


Link: CVE-2015-9290

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-07-30T13:15:12.670

Modified: 2023-11-07T02:28:58.217


Link: CVE-2015-9290

JSON object: View

cve-icon Redhat Information

No data.

CWE