CVE Vulnerabilities

CVE-2025-43903

Improper Verification of Cryptographic Signature

Published: Apr 18, 2025 | Modified: Oct 06, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
PopplerFreedesktop*25.04.0 (excluding)
PopplerUbuntuesm-infra/bionic*
PopplerUbuntuesm-infra/focal*
PopplerUbuntufocal*
PopplerUbuntujammy*
PopplerUbuntunoble*
PopplerUbuntuoracular*
PopplerUbuntuplucky*
PopplerUbuntuupstream*

References