Re: Security Report: Unbounded Composite Glyph Recursion DoS (CWE-674)

Werner LEMBERG <[email protected]> Thu, 26 Mar 2026 05:55:29 +0000
Newsgroups gmane.comp.fonts.freetype.devel
Message-ID <[email protected]>
>>> There is also no way to disclose security issues through the
>>> GitHub: https://github.com/freetype/freetype/security
>>
>> As it says on the front page of
>> https://github.com/freetype/freetype the github is just a mirror of
>> the main repo at https://gitlab.freedesktop.org/freetype/freetype
>> and if you scroll down to the README on the github you'll see it
>> also links to the gitlab to report bugs.
> 
> Still, he's not wrong that https://freetype.org/contact.html could be
> improved.
> 
> 1. explicitly mentioning contact instruction for security issues.
> 2. mentioning that the mailing lists are *public*. (a lot of my
>    young interns have never been exposed to the concept of public
>    mailing lists via email. their universe only includes things like
>    slack, discourse, etc.)

I've tried to improve the wording.  Please check!

  https://freetype.org/contact.html
  https://freetype.org/developer.html


     Werner