Command Injection in iText - CVE-2021-43113
Published: January 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation within the GhostscriptHelper.java when processing data passed via a CompareTool filename. A remote attacker can pass a specially crafted file to the application and execute arbitrary Java code on the system.
Affected software
Debian Linux
Oracle WebCenter Content
Oracle Documaker
Primavera Unifier
EMC Integrated Data Protection Appliance
libitext5-java (Debian package)
EMC Data Protection Advisor
How to mitigate CVE-2021-43113
EMC Integrated Data Protection Appliance - update to 2.7.6
libitext5-java (Debian package) - update to 5.5.13.2-1+deb11u1
EMC Data Protection Advisor - update to 19.10 PB22