CVE-2025-43903

Name
CVE-2025-43903
Description
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gitlab.freedesktop.org/poppler/poppler/-/commit/f1b9c830f145a0042e853d6462b2f9ca4016c669

Match rules

CPE URI Source package Min version Max version
poppler >= 0 < 25.04.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
poppler edge-main 24.02.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
poppler edge-main 25.01.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
poppler edge-main 25.02.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable