Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w9g-4h2x-7qxq

Опубликовано: 18 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

EPSS

Процентиль: 1%
0.0001
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 4.3
ubuntu
8 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
redhat
8 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
nvd
8 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
debian
8 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the ...

suse-cvrf
8 месяцев назад

Security update for poppler

EPSS

Процентиль: 1%
0.0001
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347