Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w9g-4h2x-7qxq

Опубликовано: 18 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

EPSS

Процентиль: 0%
0.00008
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
redhat
2 месяца назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
nvd
2 месяца назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

CVSS3: 4.3
debian
2 месяца назад

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the ...

suse-cvrf
около 2 месяцев назад

Security update for poppler

EPSS

Процентиль: 0%
0.00008
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-347