CVE-2025-43903

EUVD-2025-11892
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
freedesktoppoppler
𝑥
< 25.04.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
poppler
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
25.03.0-11.1
fixed
sid
26.01.0-4
fixed
trixie
25.03.0-5+deb13u2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libpoppler-cpp0
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed
libpoppler-devel
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed
libpoppler-glib-devel
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed
libpoppler-glib8
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed
libpoppler135
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed
poppler-tools
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed
typelib-1_0-Poppler-0_18
suse enterprise desktop 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise desktop 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise sap 15 SP7
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP6
24.03.0-150600.3.13.1
fixed
suse enterprise server 15 SP7
24.03.0-150600.3.13.1
fixed