File CVE-2012-1130.patch of Package freetype2

--- freetype-2.4.4.orig/src/pcf/pcfread.c.orig	2012-04-12 14:36:17.649853270 +0200
+++ freetype-2.4.4/src/pcf/pcfread.c	2012-04-12 14:37:23.681857673 +0200
@@ -2,7 +2,7 @@
 
     FreeType font driver for pcf fonts
 
-  Copyright 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008, 2009 by
+  Copyright 2000-2010, 2012 by
   Francesco Zappa Nardelli
 
 Permission is hereby granted, free of charge, to any person obtaining a copy
@@ -493,7 +493,8 @@
       goto Bail;
     }
 
-    if ( FT_NEW_ARRAY( strings, string_size ) )
+    /* allocate one more byte so that we have a final null byte */
+    if ( FT_NEW_ARRAY( strings, string_size + 1 ) )
       goto Bail;
 
     error = FT_Stream_Read( stream, (FT_Byte*)strings, string_size );
openSUSE Build Service is sponsored by