Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-43903

Published: April 19, 2025Last modified: June 5, 2025

Description

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Severity score breakdown

ParameterValue
Base score4.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpopplerUnknown (22.11.0-r0)
StreampopplerUnknown (23.03.0-r1)

References

ON THIS PAGE