Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-65411

Опубликовано: 30 дек. 2025
Источник: debian

Описание

A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
unrtfunfixedpackage

Примечания

  • https://hg.savannah.gnu.org/hgweb/unrtf/rev/755925d817fe

  • https://github.com/MAXEUR5/Vulnerability_Disclosures/blob/main/2025/CVE-2025-65411.md

  • Crash in CLI tool, no security impact

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.

CVSS3: 7.5
nvd
около 1 месяца назад

A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.

CVSS3: 7.5
github
около 1 месяца назад

A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.