commit | 112527dd44edc388137fdf6809ddeb9cf1a9c51f | [log] [tgz] |
---|---|---|
author | Werner Lemberg <wl@gnu.org> | Sat Jan 22 11:45:30 2022 +0100 |
committer | Werner Lemberg <wl@gnu.org> | Sat Jan 22 12:09:08 2022 +0100 |
tree | b69b87b4014b57170524902f55daaf83f105b267 | |
parent | 706c79a1da4aeb05c331f6ff0a7051e7613d5aba [diff] |
[sfnt] Reject malformed SVG tables. * src/sfnt/ttsvg.c (SVG_TABLE_HEADER_SIZE, SVG_DOCUMENT_RECORD_SIZE, SVG_DOCUMENT_LIST_MINIMUM_SIZE, SVG_MINIMUM_SIZE): New macros. (tt_face_load_svg): Check offsets. Check table and record sizes. Reported as https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=43918