A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.
{ "urgency": "unimportant" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-65411.json"