Skip to content

Update freetype to fix CVE? #4198

@fschutt

Description

@fschutt

FreeType version 2.6, which webrender depends on on Linux had a heap buffer overflow has been found in the handling of embedded PNG bitmaps.

Since webrender links freetype statically (afaik) it would make sense to update the freetype dependency to fix this issue.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions