Adobe Reader CoolType Use Of Uninitialized Memory In Transient Array

Discussion in 'News Aggregator' started by Packet Storm, 21 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    The "transient array" specified in the "Type 2 Charstring format" specs but also available in Type1 fonts (originally for the purpose of facilitating Multiple Master fonts) is allocated dynamically only if the CoolType interpreter encounters an instruction which requires the presence of the array, such as "get" or "store". While allocating the array, however, the routine does not automatically clear the contents of the newly created buffer.

    Continue reading...
     

Share This Page

Loading...