ECHO-47de-5d2a-48d4

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-47de-5d2a-48d4.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-47de-5d2a-48d4
Upstream
Withdrawn
2026-07-19T17:45:01Z
Published
2026-05-24T11:13:48Z
Modified
2026-09-15T03:33:35Z
Summary
Integer overflows in libgd (before 2.0.35) in gdImageCreate, gdImageCreateTrueColor and gdImageCopyResized on large width/height, overflowing the pixel-buffer allocation. The libgd 2.0.35 fix — the overflow2() helper and its guards on the sx*sy allocations — is already present in this trixie source: overflow2() is defined in src/extra/gd/gdhelpers.c and gdImageCreate / gdImageCreateTrueColor in src/extra/gd/gd.c bail out via overflow2(sx, sy) and the per-row size checks before allocating. There is nothing to backport; the vulnerability does not reproduce against 0.2.13. Debian rates trixie "unimportant".
Details
References

Affected packages

Echo / libwmf

Package

Name
libwmf
Purl
pkg:deb/echo/libwmf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.13-1.1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-47de-5d2a-48d4.json"