Hacker News new | past | comments | ask | show | jobs | submit login

Actually, even without hints or any other "code" parsing nontrivial formats provides opportunities for bugs causing buffer overflows or other memory corruptions. This simply shouldn't be done in the kernel, period.

However, twenty years ago (when this code likely has been written) security in the PC world was pretty much nonexistent and nobody cared about such issues.




AFAIK MS's own web browser did not support embedded fonts until IE4 in 1997.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: