NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
[
{
"id": "CVE-2025-43903-b4713ad6",
"source": "https://gitlab.freedesktop.org/poppler/poppler@f1b9c830f145a0042e853d6462b2f9ca4016c669",
"signature_version": "v1",
"digest": {
"length": 984.0,
"function_hash": "14689777309451209840247344147611302534"
},
"target": {
"function": "NSSSignatureVerification::validateSignature",
"file": "poppler/NSSCryptoSignBackend.cc"
},
"signature_type": "Function",
"deprecated": false
},
{
"id": "CVE-2025-43903-d01ff22e",
"source": "https://gitlab.freedesktop.org/poppler/poppler@f1b9c830f145a0042e853d6462b2f9ca4016c669",
"signature_version": "v1",
"digest": {
"line_hashes": [
"43529246839334217137598760692762424164",
"106889556305958527528813038992057755984",
"119146773415440100350683542563251707347",
"68074647846681240256738728870446190217",
"180935829263434236781128896326912077048",
"320692466264906605745833795675380359776",
"167526478045538800329314366218607709530",
"36773009237711217185591241177239954271",
"216287124746605493446997516677405395830"
],
"threshold": 0.9
},
"target": {
"file": "poppler/NSSCryptoSignBackend.cc"
},
"signature_type": "Line",
"deprecated": false
}
]