Debian Libitext5-Java vulnerabilities
2 known vulnerabilities affecting debian/libitext5-java.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2021-43113CRITICALCVSS 9.8fixed in libitext5-java 5.5.13.3-1 (bookworm)2021
CVE-2021-43113 [CRITICAL] CVE-2021-43113: libitext5-java - iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injecti...
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
Scope: local
bookworm: resolved (fixed in 5.5.13.3-1)
bullseye: resolved (fixed in 5.5.13.2-1+deb11u1)
forky: resolved (fixed in 5.5.13.3-1)
sid: resolved (fixe
debian
CVE-2021-37819HIGHCVSS 7.5fixed in libitext-java 2.1.7-16 (forky)2021
CVE-2021-37819 [HIGH] CVE-2021-37819: libitext-java - PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the co...
PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.1.7-16)
sid: resolved (fixed in 2.1.7-16)
trixie: resolved (fixed in 2.1.7-16)
debian