Buffer Over-read in FreeType Affects Multiple Platforms
CVE-2015-9382
6.5MEDIUM
What is CVE-2015-9382?
A vulnerability in FreeType Library prior to version 2.6.1 results in a buffer over-read during the execution of the 'skip_comment' function in 'psaux/psobjs.c'. This flaw is caused by improper handling of the 'ps_parser_skip_PS_token' within an 'FT_New_Memory_Face' operation, which may expose applications to potential exploitation avenues.