CVE-2021-43113
15.12.2021, 07:15
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
Vendor | Product | Version |
---|---|---|
itextpdf | itext | 7.0.0 ≤ 𝑥 < 7.1.17 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References