Lucene search

K
osvGoogleOSV:CVE-2021-43113
HistoryDec 15, 2021 - 7:15 a.m.

CVE-2021-43113

2021-12-1507:15:07
Google
osv.dev
12
itextpdf
command injection
filename handling
ghostscript
software security

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

71.9%

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

AI Score

7

Confidence

Low

EPSS

0.003

Percentile

71.9%