summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorWerner Lemberg <wl@gnu.org>2020-10-28 13:34:52 +0100
committerWerner Lemberg <wl@gnu.org>2020-10-28 13:34:52 +0100
commit804e625def2cfb64ef2f4c8877cd3fa11e86e208 (patch)
treeaa9b0a43d4d36cab4ade1307e1c102acc55f8270 /src
parent40c5681ab92e7db1298273ccf3c816e6a1498260 (diff)
downloadfreetype2-804e625def2cfb64ef2f4c8877cd3fa11e86e208.tar.gz
[truetype] Minor update to forthcoming OpenType 1.8.4 standard.
* src/truetype/ttgxvar.c (ft_var_load_item_variation_store): Limit size of `regionCount`.
Diffstat (limited to 'src')
-rw-r--r--src/truetype/ttgxvar.c9
1 files changed, 9 insertions, 0 deletions
diff --git a/src/truetype/ttgxvar.c b/src/truetype/ttgxvar.c
index b462263de..53b0cc26f 100644
--- a/src/truetype/ttgxvar.c
+++ b/src/truetype/ttgxvar.c
@@ -493,6 +493,15 @@
goto Exit;
}
+ /* new constraint in OpenType 1.8.4 */
+ if ( itemStore->regionCount >= 32768U )
+ {
+ FT_TRACE2(( "ft_var_load_item_variation_store:"
+ " too many variation region tables\n" ));
+ error = FT_THROW( Invalid_Table );
+ goto Exit;
+ }
+
if ( FT_NEW_ARRAY( itemStore->varRegionList, itemStore->regionCount ) )
goto Exit;