Debian Linux Security Advisory 2116-1 – Marc Schoenefeld has found an input stream position error in the way the FreeType font rendering engine processed input file streams. If a user loaded a specially-crafted font file with an application linked against FreeType and relevant font glyphs were subsequently rendered with the X FreeType library (libXft), it could cause the application to crash or, possibly execute arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/94507/dsa-2116-1.txt
Source: https://packetstormsecurity.com/files/94507/Debian-Linux-Security-Advisory-2116-1.html