CVE-2025-43903
Publication date 18 April 2025
Last updated 23 April 2025
Ubuntu priority
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
Status
Package | Ubuntu Release | Status |
---|---|---|
poppler | 25.04 plucky |
Vulnerable
|
24.10 oracular |
Vulnerable
|
|
24.04 LTS noble |
Vulnerable
|
|
22.04 LTS jammy |
Vulnerable
|
|
20.04 LTS focal |
Vulnerable
|
|
18.04 LTS bionic |
Vulnerable
|
|
16.04 LTS xenial |
Not affected
|