did it have "signature covers whole document" at the beginning of the 
output?

Tilman


------------------------------------------------------------------------
Gesendet mit der Telekom Mail App
<https://kommunikationsdienste.t-online.de/redirects/email_app_android_sendmail_footer>



--- Original-Nachricht ---
Von: Wolfgang Bauer
Betreff: PDF Signature Spoofing
Datum: 28.02.2019, 10:04 Uhr
An: users@pdfbox.apache.org





Hello everybody,

as you have probably already heard, there are currently new attacks on
pdf signatures very popular in the media.

https://www.pdf-insecurity.org <https://www.pdf-insecurity.org> /

In particular the demo doucuments of Attack 2: Incremental Saving
Attack and Attack 3 can be parsed with the pdfbox library and the
ShowSignature example even validates the malicious signatures.

Are there any plans to include some validation steps into pdfbox to
cope with these problems?

ThanksĀ 
Wolfgang

Reply via email to