View Single Post
Old 11-13-2012, 03:57 AM   #84
bhaak
Groupie
bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.bhaak can program the VCR without an owner's manual.
 
bhaak's Avatar
 
Posts: 164
Karma: 164969
Join Date: Dec 2011
Device: Palm IIIx, (iPhone|Kindle) Touch
Quote:
Originally Posted by dos1 View Post
I wonder if libfreetype on Kindle is patched against this kind of attacks:

http://esec-lab.sogeti.com/post/Anal...3-font-exploit
https://github.com/comex/star_

There is support for custom fonts in /mnt/us/fonts, we can also run PDFs or websites with embedded fonts. I think I'll dig into this over weekend, but any help will be appreciated.
Amazon is shipping a heavily stripped down (and possibly modified?) old version of libfreetype.

I haven't yet looked what libfreetype is shipping with 5.3.0 but we know that the Touch 5.1.2 version labeled libfreetype.so.6.3.20 crashes when you put DejaVu Sans into /mnt/us/fonts.

KPW 5.2.0 has the same version number as 5.1.2, so it could be worth a try.
bhaak is offline   Reply With Quote