Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w9g-4h2x-7qxq

Опубликовано: 18 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

EPSS

Процентиль: 3%
0.00016
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 4.3
ubuntu
10 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
redhat
10 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
nvd
10 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
debian
10 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the ...

suse-cvrf
9 месяцев назад

Security update for poppler

EPSS

Процентиль: 3%
0.00016
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347