NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Poppler | Ubuntu | devel | * |
Poppler | Ubuntu | esm-infra/bionic | * |
Poppler | Ubuntu | focal | * |
Poppler | Ubuntu | jammy | * |
Poppler | Ubuntu | noble | * |
Poppler | Ubuntu | oracular | * |
Poppler | Ubuntu | plucky | * |
Poppler | Ubuntu | upstream | * |