NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries. (CVE-2025-43903)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2025-0143.json"