The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < 3836029448e76c1e6f77cc5fe0adc09b018b5fa8 |