PDFFence 1.23.0 tightens PDF signature boundary checks with terminal footer rule
PDFFence 1.23.0, a static PDF analysis tool, has been updated to strengthen its signature-boundary checks by requiring that a signature revision's footer be the physical terminal footer of the file. The update refines existing rules PFP013 and PFP014 to ensure that unlinked bytes appended after a valid PDF footer are not mistakenly credited as a legitimate incremental revision. According to PDF 2.0 syntax standards, a valid incremental update must include linked cross-reference data and a proper terminal footer, a condition PDFFence now strictly enforces. The accompanying benchmark suite PDFCAB 1.23.0 adds a 160th deterministic test pair, and both tools passed their full test suites on Python 3.12 and 3.13. PDFFence remains a review aid only and does not validate signatures, certificates, or trust decisions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in