-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 23 May 2025 20:09:22 -0300 Source: yelp Binary: libyelp-dev libyelp0 libyelp0-dbgsym yelp yelp-dbgsym Architecture: amd64 Version: 42.2-1+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Lucas Kanashiro Description: libyelp-dev - Library for the GNOME help browser (development) libyelp0 - Library for the GNOME help browser yelp - Help browser for GNOME Changes: yelp (42.2-1+deb12u1) bookworm-security; urgency=medium . * Non-maintainer upload by the Security Team. * Fix CVE-2025-3155. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. - d/p/CVE-2025-3155.patch Checksums-Sha1: 4ffce8edbd665b56a3353b0a93aa813488b13ac7 75080 libyelp-dev_42.2-1+deb12u1_amd64.deb 908f9827ad27d716d76cb4d264da8f8d3d2a8bd5 340804 libyelp0-dbgsym_42.2-1+deb12u1_amd64.deb 51ee740d061f1fae6beae82087c4e0dfba9b79b6 158652 libyelp0_42.2-1+deb12u1_amd64.deb 26707f1086e2b6b219cbb4a4a91b2d52cf41570b 63672 yelp-dbgsym_42.2-1+deb12u1_amd64.deb 09ab7ef2e8b6f1e87bbdad886d0cfda4aba3f559 20955 yelp_42.2-1+deb12u1_amd64-buildd.buildinfo 8d18fcc58abc3e2298afc058b9464fc7e771438a 779632 yelp_42.2-1+deb12u1_amd64.deb Checksums-Sha256: 7c4c1b5f0b7b550be67bb9b51cd723f62fe1bdd45c66d2a2ccf7610aa9550756 75080 libyelp-dev_42.2-1+deb12u1_amd64.deb ab8a3ea36c099dde40824ed126175ba21185b7a215c32c582dcf681a0b27fc11 340804 libyelp0-dbgsym_42.2-1+deb12u1_amd64.deb 9bb289ed72a83f4ef4625e78c225635bf9ef8ffe78204aa6a1ef87e47b072098 158652 libyelp0_42.2-1+deb12u1_amd64.deb a0a746a9b435cad95cc993727b8c75c2ceb014944ab1b040a13937dbf3c7e1ef 63672 yelp-dbgsym_42.2-1+deb12u1_amd64.deb f934374a8b2eeeac3ed92297a26918c2c26a69fd014f2945bc528e0cfb52ded2 20955 yelp_42.2-1+deb12u1_amd64-buildd.buildinfo 8093bf2db2ffd85198cdf1992185f91c6925d56a92406d41e1665dcf4f0628a0 779632 yelp_42.2-1+deb12u1_amd64.deb Files: d7ddcf3ebd4a7666cd088e78eb9e6581 75080 libdevel optional libyelp-dev_42.2-1+deb12u1_amd64.deb 8e5d57fca84ceeb107795d072522da53 340804 debug optional libyelp0-dbgsym_42.2-1+deb12u1_amd64.deb bbdd24af466dccb80d5e9a2192a093ec 158652 libs optional libyelp0_42.2-1+deb12u1_amd64.deb d55d0343f85916dd559a4931c31d7881 63672 debug optional yelp-dbgsym_42.2-1+deb12u1_amd64.deb 729d3f26c3b169bc2cacf31cc1ba110c 20955 gnome optional yelp_42.2-1+deb12u1_amd64-buildd.buildinfo 975e618936aaabe48fa33237298a4bd1 779632 gnome optional yelp_42.2-1+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmg0vnsACgkQEbCLukZn 24q2tA//YYKLHUUsQ61/QSVIP2DdW/5bkly5EiiZSeOXYiJlIvlP4YmJabEYPYrK hXl78AXLuMNWvKi3ny01m+s1YayiTGKWDE1DGArtTNwEz2bG2mkmOGvAY76HmykI f1la725OgjYWjdKV0uLFJkmCoSqGw274IQRL0jPHLIOwK/BApb1xGbnVLPYBPZ5/ hXvYBx/IAcowowZPI4GnI/hkKgWzby/hed7HYCAFllmCNNg4eiCtDdiixzEf4cl9 7tVoqq3xMzIR6uAUtnZINUhiIAdhFTxyq31GYrCAz8zEdEuJyDj0tmgL1/74I4/0 3xVfgCPmv3Hs4Jw7uAiCovfmYxkXx+XyOadiqICHin964emPoKctqN6L1rCx8s8c piY8UhlyjjKoOLsxnYfMMcaoRrsTApA1wV3qjCuyr4w8xTH9sL6f8kXaNaUq78jQ telzcRFLLmYsfPX5NF1KaTvxM4E7CTvOLcwgV+t0PDoE9lc+vZgcUml9JewDDXdf 6LVVfY3u6fjuLOjTOKSZGESX9JOWWxmX5Era+McF9TOSxDHpMHRynUVpmk8xiZVs kKqoL/7qOwcQ61n7HCQEFwYxqIlzRRZs2giyEiOLbO5+ZAkhH/z68h91j1i88gDf a/bURgvrRX9phEahsLd123f4n87M2m6UI8LAnBJuiK5S9VjWtTs= =n4t0 -----END PGP SIGNATURE-----