ae68a7
From 29c759284e305ec428703c9a5831d0b1fc3497ef Mon Sep 17 00:00:00 2001
ae68a7
From: Werner Lemberg <wl@gnu.org>
ae68a7
Date: Sat, 27 Jan 2018 14:43:43 +0100
ae68a7
Subject: [PATCH] * src/truetype/ttinterp.c (Ins_GETVARIATION): Avoid NULL
ae68a7
 reference.
ae68a7
ae68a7
Reported as
ae68a7
ae68a7
  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5736
ae68a7
---
ae68a7
 src/truetype/ttinterp.c | 12 ++++++++++--
ae68a7
 1 files changed, 10 insertions(+), 2 deletions(-)
ae68a7
ae68a7
diff --git a/src/truetype/ttinterp.c b/src/truetype/ttinterp.c
ae68a7
index d855aaaa9..551f14a2e 100644
ae68a7
--- a/src/truetype/ttinterp.c
ae68a7
+++ b/src/truetype/ttinterp.c
ae68a7
@@ -7470,8 +7470,16 @@
ae68a7
       return;
ae68a7
     }
ae68a7
 
ae68a7
-    for ( i = 0; i < num_axes; i++ )
ae68a7
-      args[i] = coords[i] >> 2; /* convert 16.16 to 2.14 format */
ae68a7
+    if ( coords )
ae68a7
+    {
ae68a7
+      for ( i = 0; i < num_axes; i++ )
ae68a7
+        args[i] = coords[i] >> 2; /* convert 16.16 to 2.14 format */
ae68a7
+    }
ae68a7
+    else
ae68a7
+    {
ae68a7
+      for ( i = 0; i < num_axes; i++ )
ae68a7
+        args[i] = 0;
ae68a7
+    }
ae68a7
   }
ae68a7
 
ae68a7
 
ae68a7
-- 
ae68a7
2.14.3
ae68a7