ECHO-a7ed-bfec-5fe3

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-a7ed-bfec-5fe3.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-a7ed-bfec-5fe3
Upstream
Withdrawn
2026-07-19T17:45:01Z
Published
2026-05-24T11:13:48Z
Modified
2026-09-15T03:33:35Z
Summary
Array index error in gd_gif_in.c in the bundled GD graphics library (libgd before 2.0.35), reached via the GIF reader (gdImageCreateFromGif). libwmf carries its own copy of GD under src/extra/gd and compiles it (Debian does not build-depend on libgd-dev, so LIBWMF_OPT_SYS_GD is off), but that copy ships no GIF reader at all: there is no gd_gif_in.c/gd_gif_out.c and libgd_la_SOURCES in src/extra/gd/Makefile.am compiles no GIF source. libwmf uses GD only as a rasterization/output backend and never decodes GIF input. The vulnerable code is not present or reachable in this package; scanners flag it only via Debian's stale source-package match (trixie is "unimportant / unfixed" while standalone libgd2 is fixed).
Details
References

Affected packages

Echo / libwmf

Package

Name
libwmf
Purl
pkg:deb/echo/libwmf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.13-1.1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-a7ed-bfec-5fe3.json"