Accepting request 796116 from home:alarrosa:branches:M17N

* Fixes use-after-free (heap) in the SFD_GetFontMetaData()
    function and fix NULL pointer dereference in the
    SFDGetSpiros() and SFD_AssignLookups() function(bnc#1160220,
    bnc#1160236, CVE-2020-5395, CVE-2020-5496).

OBS-URL: https://build.opensuse.org/request/show/796116
OBS-URL: https://build.opensuse.org/package/show/M17N/fontforge?expand=0&rev=75
This commit is contained in:
Marguerite Su 2020-04-22 08:42:58 +00:00 committed by Git OBS Bridge
parent e6d72c9358
commit 7f433e441d

View File

@ -52,6 +52,10 @@ Wed Apr 15 18:30:12 UTC 2020 - Antonio Larrosa <alarrosa@suse.com>
against, nor are the headers actually well configured to be against, nor are the headers actually well configured to be
used externally. We are also not aware of any maintained used externally. We are also not aware of any maintained
product that compiles against FontForge itself. product that compiles against FontForge itself.
* Fixes use-after-free (heap) in the SFD_GetFontMetaData()
function and fix NULL pointer dereference in the
SFDGetSpiros() and SFD_AssignLookups() function(bnc#1160220,
bnc#1160236, CVE-2020-5395, CVE-2020-5496).
- Drop patch that isn't needed anymore: - Drop patch that isn't needed anymore:
* python38_config.patch * python38_config.patch