ECHO-dd6d-14c6-050c

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-dd6d-14c6-050c.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-dd6d-14c6-050c
Upstream
Withdrawn
2025-10-29T09:06:55Z
Published
2025-09-15T01:12:08Z
Modified
2026-09-15T03:33:39Z
Summary
The vulnerability report for CVE-2025-29480 has been disputed by the GDAL maintainers, since it could not be reproduced. https://github.com/OSGeo/gdal/issues/12188 The report that got the cve: https://github.com/lmarch2/poc/blob/main/gdal/gdal.md It does seem vague, and there was no follow-up. https://security-tracker.debian.org/tracker/CVE-2025-29480 We should definitely track this and see if there is an update.
Details
References

Affected packages

Echo / gdal

Package

Name
gdal
Purl
pkg:deb/echo/gdal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.10.3+dfsg-1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-dd6d-14c6-050c.json"