CVE-2021-43113

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
15/12/2021
Last modified:
24/03/2023

Description

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:itextpdf:itext:*:*:*:*:*:*:*:* 7.0.0 (including) 7.1.17 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*