CVE Vulnerabilities

CVE-2025-43903

Improper Verification of Cryptographic Signature

Published: Apr 18, 2025 | Modified: Apr 21, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Ubuntu
MEDIUM

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Poppler Ubuntu devel *
Poppler Ubuntu esm-infra/bionic *
Poppler Ubuntu focal *
Poppler Ubuntu jammy *
Poppler Ubuntu noble *
Poppler Ubuntu oracular *
Poppler Ubuntu plucky *
Poppler Ubuntu upstream *

References