{"id":"ECHO-966c-4616-acc0","summary":"CPU-consumption DoS in gdImageArc/gdImageFilledArc (libgd before 2.0.35) via\na very large start/end angle, which drove the unbounded arc loop. The libgd\n2.0.35 fix — normalizing the angles and clamping the sweep to \u003c= 360 before\nthe drawing loop — is already present in this trixie source: gdImageFilledArc\nin src/extra/gd/gd.c reduces s/e modulo 360 and rewinds e to s (the block\npreceding \"for (i = s; (i \u003c= e); i++)\"), so the loop runs at most ~720\niterations regardless of the requested angle. There is nothing to backport;\nthe vulnerability does not reproduce against 0.2.13. Debian rates trixie\n\"unimportant\".\n","modified":"2026-09-15T03:33:35.794694839Z","published":"2026-05-24T11:13:48.707Z","withdrawn":"2026-07-19T17:45:01.763Z","upstream":["CVE-2007-3477"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2007-3477"}],"affected":[{"package":{"name":"libwmf","ecosystem":"Echo","purl":"pkg:deb/echo/libwmf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.13-1.1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-966c-4616-acc0.json"}}],"schema_version":"1.9.0"}