ECHO-966c-4616-acc0

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-966c-4616-acc0.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-966c-4616-acc0
Upstream
Withdrawn
2026-07-19T17:45:01Z
Published
2026-05-24T11:13:48Z
Modified
2026-09-15T03:33:35Z
Summary
CPU-consumption DoS in gdImageArc/gdImageFilledArc (libgd before 2.0.35) via a very large start/end angle, which drove the unbounded arc loop. The libgd 2.0.35 fix — normalizing the angles and clamping the sweep to <= 360 before the drawing loop — is already present in this trixie source: gdImageFilledArc in src/extra/gd/gd.c reduces s/e modulo 360 and rewinds e to s (the block preceding "for (i = s; (i <= e); i++)"), so the loop runs at most ~720 iterations regardless of the requested angle. There is nothing to backport; the vulnerability does not reproduce against 0.2.13. Debian rates trixie "unimportant".
Details
References

Affected packages

Echo / libwmf

Package

Name
libwmf
Purl
pkg:deb/echo/libwmf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.13-1.1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-966c-4616-acc0.json"