VYPR
Critical severity9.8NVD Advisory· Published Dec 15, 2021· Updated Jun 17, 2026

CVE-2021-43113

CVE-2021-43113

Description

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.itextpdf:itext7-coreMaven
< 7.1.177.1.17
com.itextpdf:itextpdfMaven
< 5.5.13.35.5.13.3

Affected products

6
  • Itextpdf/Itext2 versions
    cpe:2.3:a:itextpdf:itext:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:itextpdf:itext:*:*:*:*:*:*:*:*range: >=7.0.0,<7.1.17
    • (no CPE)
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    < 7.1.17+ 1 more
    • (no CPE)range: < 7.1.17
    • (no CPE)range: < 5.5.13.3

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.