iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
| Software | From | Fixed in |
|---|---|---|
| itextpdf / itext | 7.0.0 | 7.1.17 |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |
com.itextpdf / itext7-core
|
- | 7.1.17 |
com.itextpdf / itextpdf
|
- | 5.5.13.3 |