GHSA-gv87-q66h-4277
CRITICALCVE-2021-43113iTextPDF in iText before 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
- Affected
- < 5.5.13.3
- Fixed in
- 5.5.13.3
- Weakness
- CWE-77
- Published
- 2021-12-16
- Source
- github