Fedora has issued an advisory today (December 8): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UKXGAHTBXYEQGJAG6MQPCH7QNBP5SY7S/ This is in the original woff, but woff2 should be checked to see if it's affected too. If so, Mageia 8 is also affected.
Jean-pierre (pol4n) has updated this package recently, so assigning to you. If this is not right, please re-assign it to pkg-bugs.
Assignee: bugsquad => jean-pierre
I checked wolff2 source code and I confirm that wolff2 is NOT affected by this double free security issue!
CC: (none) => geiger.david68210
Thanks!
Resolution: (none) => INVALIDStatus: NEW => RESOLVED