CVE Vulnerabilities

CVE-2025-43903

Improper Verification of Cryptographic Signature

Published: Apr 18, 2025 | Modified: Apr 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

References