Accepting request 796116 from home:alarrosa:branches:M17N

* Fixes use-after-free (heap) in the SFD_GetFontMetaData()
    function and fix NULL pointer dereference in the
    SFDGetSpiros() and SFD_AssignLookups() function(bnc#1160220,
    bnc#1160236, CVE-2020-5395, CVE-2020-5496).

OBS-URL: https://build.opensuse.org/request/show/796116
OBS-URL: https://build.opensuse.org/package/show/M17N/fontforge?expand=0&rev=75
This commit is contained in:
Marguerite Su 2020-04-22 08:42:58 +00:00 committed by Git OBS Bridge
parent e6d72c9358
commit 7f433e441d

View File

@ -52,6 +52,10 @@ Wed Apr 15 18:30:12 UTC 2020 - Antonio Larrosa <alarrosa@suse.com>
against, nor are the headers actually well configured to be
used externally. We are also not aware of any maintained
product that compiles against FontForge itself.
* Fixes use-after-free (heap) in the SFD_GetFontMetaData()
function and fix NULL pointer dereference in the
SFDGetSpiros() and SFD_AssignLookups() function(bnc#1160220,
bnc#1160236, CVE-2020-5395, CVE-2020-5496).
- Drop patch that isn't needed anymore:
* python38_config.patch