https://bugzilla.redhat.com/show_bug.cgi?id=1574125
--- Comment #1 from Xose Vazquez Perez xose.vazquez@gmail.com --- (In reply to Upstream Release Monitoring from comment #0)
Latest upstream release: 2.9.1 Current version/release in rawhide: 2.9-1.fc29 URL: https://www.freetype.org/ Based on the information from anitya: https://release-monitoring.org/project/854/
This is a maintenance release; most importantly fixing correct handling of Type 1 fonts with flex features, which was broken in version 2.9. All users should upgrade.
CHANGES BETWEEN 2.9 and 2.9.1
I. IMPORTANT BUG FIXES
- Type 1 fonts containing flex features were not rendered correctly (bug introduced in version 2.9).
- CVE-2018-6942: Older FreeType versions can crash with certain malformed variation fonts.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6942
II. MISCELLANEOUS
- Bug fix: Multiple calls to `FT_Get_MM_Var' returned garbage.
- The base extensions `ftlcdfil' and `ftfntfmt' are now part of the base module (and thus no longer configurable in file `modules.cfg').
- Emboldening of bitmaps didn't work correctly sometimes, showing various artifacts (bug introduced in version 2.8.1).
- Use of the `freetype-config' script to get compilation and linking options is deprecated since it doesn't support cross-compiling, among other deficiencies. Instead, you should use the `pkg-config' interface.
The `configure' script no longer installs `freetype-config' by default. For backwards compatibility, a new configure option `--enable-freetype-config' is provided that reverts this decision.
- The auto-hinter script ranges have been updated for Unicode 11. No support for new scripts have been added, however, with the exception of Georgian Mtavruli.
- Support for cmake has been improved.
- The next release will remove support for Position Independent Code as needed by systems that prohibit automatic address fixups, such as BREW. [Compilation with modern compilers that use flags like `-fPIC' or `-fPIE' is not affected.]