PT-2025-17348 · Poppler+7 · Poppler+7

Published

2025-04-01

·

Updated

2026-04-13

·

CVE-2025-43903

CVSS v3.1

4.3

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Poppler versions prior to 25.04.0
Description The issue is related to the verification of adbe.pkcs7.sha1 signatures on documents. In the affected versions, the NSSCryptoSignBackend.cc in Poppler does not properly verify these signatures, which could result in potential signature forgeries.
Recommendations For versions prior to 25.04.0, update to version 25.04.0 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14450
BDU:2025-06076
CVE-2025-43903
ECHO-9071-56C9-378A
JLSEC-2026-87
MGASA-2025-0143
OESA-2025-1476
OESA-2025-1477
OESA-2025-2520
OESA-2025-2521
OESA-2025-2522
OPENSUSE-SU-2025_1434-1
SUSE-SU-2025:1434-1
SUSE-SU-2025_1434-1
USN-7471-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Poppler
Red Os
Suse
Ubuntu