It was discovered that GD.pm incorrectly handled filename arguments. An
attacker could possibly use this issue to execute arbitrary commands or
overwrite files.