{"id":"ECHO-dd6d-14c6-050c","summary":"The vulnerability report for CVE-2025-29480 has been disputed by the GDAL maintainers, since it could not be reproduced.\nhttps://github.com/OSGeo/gdal/issues/12188\nThe report that got the cve: https://github.com/lmarch2/poc/blob/main/gdal/gdal.md\nIt does seem vague, and there was no follow-up.\nhttps://security-tracker.debian.org/tracker/CVE-2025-29480\nWe should definitely track this and see if there is an update.\n","modified":"2026-09-15T03:33:39.331279748Z","published":"2025-09-15T01:12:08.713938Z","withdrawn":"2025-10-29T09:06:55.770Z","upstream":["CVE-2025-29480"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-29480"}],"affected":[{"package":{"name":"gdal","ecosystem":"Echo","purl":"pkg:deb/echo/gdal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.3+dfsg-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-dd6d-14c6-050c.json"}}],"schema_version":"1.9.0"}