Command Injection in iText - CVE-2021-43113

 

Command Injection in iText - CVE-2021-43113

Published: January 20, 2023


Vulnerability identifier: #VU71373
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43113
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper input validation within the GhostscriptHelper.java when processing data passed via a CompareTool filename. A remote attacker can pass a specially crafted file to the application and execute arbitrary Java code on the system.


Affected software

iText
Debian Linux
Oracle WebCenter Content
Oracle Documaker
Primavera Unifier
EMC Integrated Data Protection Appliance
libitext5-java (Debian package)
EMC Data Protection Advisor

How to mitigate CVE-2021-43113

Install updates from vendor's website.

iText - update to 7.1.17
EMC Integrated Data Protection Appliance - update to 2.7.6
libitext5-java (Debian package) - update to 5.5.13.2-1+deb11u1
EMC Data Protection Advisor - update to 19.10 PB22

External References

Related Security Bulletins