https://bugzilla.redhat.com/show_bug.cgi?id=1241552
--- Comment #1 from Peter TB Brett peter@peter-b.co.uk --- I ran some more tests. The following builds contain the buffer overrun bug:
- pango-1.36.8-5.fc22.x86_64 package - Build from pango-1.36.8.tar.xz archive - Build from pango git, tag 1.36.8
The following builds do *not* contain the buffer overrun:
- Build from pango git, tag 1.37.0 - Build from pango git, tag 1.37.1
Bisect indicates that the bug is fixed in upstream commit fafc7915: https://git.gnome.org/browse/pango/commit/?id=fafc7915334be2dc7eb3952ea05988...
That patch applies cleanly against 1.36.8, but backporting that patch alone doesn't appear to fix the issue.
Could 1.37.0 be built and distributed through F22 "updates" repo, please?