freetype-commit
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Git][freetype/freetype][master] * src/truetype/ttgxvar.c (ft_var_to_nor


From: Werner Lemberg (@wl)
Subject: [Git][freetype/freetype][master] * src/truetype/ttgxvar.c (ft_var_to_normalized): Integer overflow.
Date: Fri, 23 Feb 2024 10:57:06 +0000

Werner Lemberg pushed to branch master at FreeType / FreeType

Commits:

  • 546237e1
    by Werner Lemberg at 2024-02-23T11:55:53+01:00
    * src/truetype/ttgxvar.c (ft_var_to_normalized): Integer overflow.
    
    Reported as
    
      https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=66543
    

1 changed file:

Changes:

  • src/truetype/ttgxvar.c
    ... ... @@ -2142,7 +2142,7 @@
    2142 2142
                                              innerIndex );
    
    2143 2143
     
    
    2144 2144
               /* Convert to 16.16 format before adding. */
    
    2145
    -	  v += delta * 4;
    
    2145
    +	  v += MUL_INT( delta, 4 );
    
    2146 2146
     
    
    2147 2147
     	  /* Clamp value range. */
    
    2148 2148
     	  v = v >=  0x10000L ?  0x10000 : v;
    


  • reply via email to

    [Prev in Thread] Current Thread [Next in Thread]