CVE-2021-43113
9.8
CRITICAL · CVSS 3.1 · EPSS 5.2% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.22% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-12-15 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| itextpdf | itext |
References
- https://github.com/itext/itext7/releases/tag/7.1.17
- https://github.com/itext/itextpdf/releases/tag/5.5.13.3
- https://lists.debian.org/debian-lts-announce/2023/01/msg00013.html
- https://pastebin.com/BXnkY9YY
- https://www.debian.org/security/2023/dsa-5323
- https://github.com/itext/itext7/releases/tag/7.1.17
- https://github.com/itext/itextpdf/releases/tag/5.5.13.3
- https://lists.debian.org/debian-lts-announce/2023/01/msg00013.html
- https://pastebin.com/BXnkY9YY
- https://www.debian.org/security/2023/dsa-5323
→ the Explorer · watch your stack · NVD