To get an out-of-bounds write, the attacker simply has to specify a start_line value greater than the number of lines in the output canvas. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9634