CVE-2025-43903

Updated on 18 Apr 2025

Severity

3.3 Low severity

Details

CVSS score
3.3
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Overview

About vulnerability

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Details

Affected product:
AlmaLinux 9.2 ESU
Affected packages:
poppler @ 21.01.0
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.