yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-43903
Component Overview
Vulnerability Overview
Name
CVE-2025-43903
Source
NVD (
link
)
Debian (
link
)
Description
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
CWEs
CWE-347
Published Date
Apr 18, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/poppler/poppler/-/commit/f1b9c830f145a0042e853d6462b2f9ca4016c669
Patch
Analysis
#
Affected Component
Analysis
poppler
Patched
Vulnerability Ratings
#
4.3
CVSSv31
3.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
poppler
buildroot
2025.02.x
25.10.0
Not Affected
poppler
buildroot
master
25.10.0
Not Affected
poppler
yocto
master
25.12.0
Not Affected
poppler
yocto
scarthgap
23.04.0
Patched
Resolved with patches
#
poppler (yocto:kirkstone)
#
Title
Author
Resolve
1
Properly verify adbe.pkcs7.sha1 signatures.
Juraj sarinay <juraj@sarinay.com>
CVE-2025-43903
poppler (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix crash with weird hashing used for signatures
Sune Vuorela <sune@vuorela.dk>
CVE-2025-43903
2
Properly verify adbe.pkcs7.sha1 signatures.
Juraj sarinay <juraj@sarinay.com>
CVE-2025-43903