CVE-2025-43903
EUVD-2025-1189218.04.2025, 21:15
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| freedesktop | poppler | 𝑥 < 25.04.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpoppler-cpp0 |
| ||||||||||||
| libpoppler-devel |
| ||||||||||||
| libpoppler-glib-devel |
| ||||||||||||
| libpoppler-glib8 |
| ||||||||||||
| libpoppler135 |
| ||||||||||||
| poppler-tools |
| ||||||||||||
| typelib-1_0-Poppler-0_18 |
|
Common Weakness Enumeration