It was found that unrtf is vulnerable to multiple buffer overflow flaws in cmd functions. If any exposed application uses unrtf to process untrusted input, these flaws might lead to a denial-of-service.
References:
http://seclists.org/oss-sec/2016/q4/786
Originally reported in:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=849705
Patch:
http://hg.savannah.gnu.org/hgweb/unrtf/rev/3b16893a6406