An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Freetype | Freetype | * | 2.9 (including) |
| Freetype | Ubuntu | artful | * |
| Freetype | Ubuntu | devel | * |