CVE-2015-9382: Debian Linux
Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.
FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.
Affected products
Published 2019-09-03. Last modified 2026-06-17.