CVE-2021-43113

NameCVE-2021-43113
DescriptioniTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3273-1, DSA-5323-1
Debian Bugs1014597

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libitext5-java (PTS)jessie5.5.3-2vulnerable
stretch5.5.6-2vulnerable
buster (security), buster, buster (lts)5.5.13-1+deb10u1fixed
bullseye (security), bullseye5.5.13.2-1+deb11u1fixed
bookworm5.5.13.3-2fixed
sid, trixie5.5.13.3-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libitext5-javasourcejessie(unfixed)end-of-life
libitext5-javasourcestretch(unfixed)end-of-life
libitext5-javasourcebuster5.5.13-1+deb10u1DLA-3273-1
libitext5-javasourcebullseye5.5.13.2-1+deb11u1DSA-5323-1
libitext5-javasource(unstable)5.5.13.3-11014597

Notes

https://github.com/itext/itextpdf/commit/ce8bbacd631e13717a91f02e9cbd9814b9dc2cca (5.5.13.3)

Search for package or bug name: Reporting problems