freetype-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [ft-devel] [freetype2] hooks-via-module-property d94f52b: Use `FT_Pr


From: Moazin Khatri
Subject: Re: [ft-devel] [freetype2] hooks-via-module-property d94f52b: Use `FT_Property_Set' to set the hooks. One less API function.
Date: Thu, 22 Aug 2019 01:27:50 +0500

A valid concern.  However, this will definitely not happen – how will
you specify four or even more C function pointers within an
environment variable?  [...]

I am not sure if what I am going to say is correct or not. Please correct
me if I get this wrong.

I think what Behdad means is this:
The whole environment variable thing is a string, so a sequence of bytes.
If I set FREETYPE_PROPERTIES to `ot-svg:svg_hooks=asdjkfsjlfdk',
In `ft_svg_property_set', `value' will have the address of letter `a' and thus,
when the types are cast to hooks, weird address will be set and when
the `ot-svg' module calls my hooks, things will crash. I am no expert in
security, but I think this could be a security concern too? 

reply via email to

[Prev in Thread] Current Thread [Next in Thread]