Critical severity9.8NVD Advisory· Published Dec 15, 2021· Updated Jun 17, 2026
CVE-2021-43113
CVE-2021-43113
Description
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.itextpdf:itext7-coreMaven | < 7.1.17 | 7.1.17 |
com.itextpdf:itextpdfMaven | < 5.5.13.3 | 5.5.13.3 |
Affected products
6- iTextPDF/iTextdescription
- ghsa-coords2 versions
< 7.1.17+ 1 more
- (no CPE)range: < 7.1.17
- (no CPE)range: < 5.5.13.3
Patches
Vulnerability mechanics
References
7- pastebin.com/BXnkY9YYnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gv87-q66h-4277ghsaADVISORY
- github.com/itext/itext7/releases/tag/7.1.17nvdRelease NotesThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2023/01/msg00013.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-43113ghsaADVISORY
- www.debian.org/security/2023/dsa-5323nvdThird Party AdvisoryWEB
- github.com/itext/itextpdf/releases/tag/5.5.13.3nvdWEB
News mentions
0No linked articles in our index yet.