Re: Security Report: Unbounded Composite Glyph Recursion DoS (CWE-674)
Werner LEMBERG <[email protected]> Thu, 26 Mar 2026 05:55:29 +0000
| Newsgroups | gmane.comp.fonts.freetype.devel |
|---|---|
| Message-ID | <[email protected]> |
>>> There is also no way to disclose security issues through the
>>> GitHub: https://github.com/freetype/freetype/security
>>
>> As it says on the front page of
>> https://github.com/freetype/freetype the github is just a mirror of
>> the main repo at https://gitlab.freedesktop.org/freetype/freetype
>> and if you scroll down to the README on the github you'll see it
>> also links to the gitlab to report bugs.
>
> Still, he's not wrong that https://freetype.org/contact.html could be
> improved.
>
> 1. explicitly mentioning contact instruction for security issues.
> 2. mentioning that the mailing lists are *public*. (a lot of my
> young interns have never been exposed to the concept of public
> mailing lists via email. their universe only includes things like
> slack, discourse, etc.)
I've tried to improve the wording. Please check!
https://freetype.org/contact.html
https://freetype.org/developer.html
Werner