shithub: freetype+ttf2subf

Download patch

ref: d9ff6f20ad3e5101dbed0164cbed10e0d0c26792
parent: 981c23b75eb78ea2e30bf70643d61ab603453bc9
author: Werner Lemberg <[email protected]>
date: Thu Mar 16 16:20:51 EDT 2017

* src/truetype/ttgxvar.c (tt_done_blend): Free `vvar_table'.

Reported as

  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=883

git/fs: mount .git/fs: mount/attach disallowed
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,11 @@
+2017-03-16  Werner Lemberg  <[email protected]>
+
+	* src/truetype/ttgxvar.c (tt_done_blend): Free `vvar_table'.
+
+	Reported as
+
+	  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=883
+
 2017-03-15  Werner Lemberg  <[email protected]>
 
 	Remove clang compiler warnings (#50548).
--- a/src/truetype/ttgxvar.c
+++ b/src/truetype/ttgxvar.c
@@ -3696,6 +3696,16 @@
         FT_FREE( blend->hvar_table );
       }
 
+      if ( blend->vvar_table )
+      {
+        ft_var_done_item_variation_store( face,
+                                          &blend->vvar_table->itemStore );
+
+        FT_FREE( blend->vvar_table->widthMap.innerIndex );
+        FT_FREE( blend->vvar_table->widthMap.outerIndex );
+        FT_FREE( blend->vvar_table );
+      }
+
       if ( blend->mvar_table )
       {
         ft_var_done_item_variation_store( face,