A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unrtf | Unrtf_project | 0.21.10 (including) | 0.21.10 (including) |
| Unrtf | Ubuntu | plucky | * |