There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libgxps | Gnome | 0.2.5 (including) | 0.2.5 (including) |
| Libgxps | Ubuntu | upstream | * |
| Libgxps | Ubuntu | zesty | * |