Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w9g-4h2x-7qxq

Опубликовано: 18 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

EPSS

Процентиль: 13%
0.00042
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 4.3
ubuntu
12 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
redhat
12 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
nvd
12 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
debian
12 месяцев назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the ...

suse-cvrf
11 месяцев назад

Security update for poppler

EPSS

Процентиль: 13%
0.00042
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347