CVE-2021-43113

NameCVE-2021-43113
DescriptioniTextPDF in iText 7 and up to 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs1014597

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libitext5-java (PTS)buster5.5.13-1vulnerable
bullseye5.5.13.2-1vulnerable
bookworm, sid5.5.13.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libitext5-javasource(unstable)5.5.13.3-11014597

Notes

https://github.com/itext/itextpdf/commit/ce8bbacd631e13717a91f02e9cbd9814b9dc2cca (5.5.13.3)

Search for package or bug name: Reporting problems