Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-43113

Опубликовано: 15 дек. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

needs-triage

esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

needs-triage

esm-apps/xenial

not-affected

code not present
focal

not-affected

code not present
impish

not-affected

code not present
jammy

not-affected

code not present

Показывать по

EPSS

Процентиль: 85%
0.02628
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

CVSS3: 9.8
debian
около 4 лет назад

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows comma ...

CVSS3: 9.8
github
около 4 лет назад

Command injection in itext7-core

EPSS

Процентиль: 85%
0.02628
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3