font/sfnt: verify the total number of contour points

The SFNT file format explicitly lists the number of points in each
simple (non-compound) glyph and, in this package, this is loaded in func
loadGlyf as the numPoints variable. numPoints is then passed to func
findXYIndexes to verify that the (variable length) remaning glyph data
has content for that many points. loadGlyf then uses a glyfIter to
iterate over those points, but prior to this commit, fails to enforce
that the glyfIter also honors numPoints when walking each contour of a
glyph. This can lead to a panic (slice index out of bounds) on a
malformed SFNT file, if glyfIter then tries to walk too many points.

Fixes golang/go#48006

Change-Id: I92530e570eb37ce0087927ca23060acebe0a7705
Reviewed-by: Andrew Gerrand <>
Trust: Nigel Tao <>
1 file changed
tree: e7af446dbcd4b726a527641e7bced6434f43b9aa
  1. .gitattributes
  2. .gitignore
  9. bmp/
  10. ccitt/
  11. cmd/
  12. codereview.cfg
  13. colornames/
  14. draw/
  15. example/
  16. font/
  17. go.mod
  18. go.sum
  19. math/
  20. riff/
  21. testdata/
  22. tiff/
  23. vector/
  24. vp8/
  25. vp8l/
  26. webp/

Go Images

Go Reference

This repository holds supplementary Go image libraries.


The easiest way to install is to run go get -u You can also manually git clone the repository to $GOPATH/src/

Report Issues / Send Patches

This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see

The main issue tracker for the image repository is located at Prefix your issue with “x/image:” in the subject line, so it is easy to find.