Gnu · Gnu Unrtf · CVE-2025-65411
**Name of the Vulnerable Software and Affected Versions**
GNU Unrtf versions 0.21.10
**Description**
A flaw exists in the src/path.c component of GNU Unrtf that can lead to a Denial of Service (DoS). The issue is due to a NULL pointer dereference triggered by a crafted payload injected into the `search path` parameter.
**Recommendations**
Update to a newer version of GNU Unrtf that addresses this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.