Advisories ยป MGASA-2025-0143

Updated poppler packages fix security vulnerabilitiy

Publication date: 05 May 2025
Modification date: 05 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-43903

Description

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the
adbe.pkcs7.sha1 signatures on documents, resulting in potential
signature forgeries. (CVE-2025-43903)
                

References

SRPMS

9/core