{"id":"ECHO-a7ed-bfec-5fe3","upstream":["CVE-2007-3476"],"severity":[],"modified":"2026-07-19T17:45:01.763Z","affected":[{"package":{"ecosystem":"Echo","name":"libwmf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.13-1.1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2007-3476"}],"withdrawn":"2026-07-19T17:45:01.763Z","summary":"Array index error in gd_gif_in.c in the bundled GD graphics library (libgd\nbefore 2.0.35), reached via the GIF reader (gdImageCreateFromGif). libwmf\ncarries its own copy of GD under src/extra/gd and compiles it (Debian does\nnot build-depend on libgd-dev, so LIBWMF_OPT_SYS_GD is off), but that copy\nships no GIF reader at all: there is no gd_gif_in.c/gd_gif_out.c and\nlibgd_la_SOURCES in src/extra/gd/Makefile.am compiles no GIF source. libwmf\nuses GD only as a rasterization/output backend and never decodes GIF input.\nThe vulnerable code is not present or reachable in this package; scanners\nflag it only via Debian's stale source-package match (trixie is \"unimportant\n/ unfixed\" while standalone libgd2 is fixed).\n"}