{"id":"ECHO-47de-5d2a-48d4","upstream":["CVE-2007-3996"],"severity":[],"modified":"2026-07-19T17:45:01.763Z","affected":[{"package":{"ecosystem":"Echo","name":"libwmf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.13-1.1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2007-3996"}],"withdrawn":"2026-07-19T17:45:01.763Z","summary":"Integer overflows in libgd (before 2.0.35) in gdImageCreate,\ngdImageCreateTrueColor and gdImageCopyResized on large width/height,\noverflowing the pixel-buffer allocation. The libgd 2.0.35 fix — the\noverflow2() helper and its guards on the sx*sy allocations — is already\npresent in this trixie source: overflow2() is defined in\nsrc/extra/gd/gdhelpers.c and gdImageCreate / gdImageCreateTrueColor in\nsrc/extra/gd/gd.c bail out via overflow2(sx, sy) and the per-row size checks\nbefore allocating. There is nothing to backport; the vulnerability does not\nreproduce against 0.2.13. Debian rates trixie \"unimportant\".\n"}