-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 23 May 2025 20:09:22 -0300 Source: yelp Binary: libyelp-dev libyelp0 libyelp0-dbgsym yelp yelp-dbgsym Architecture: i386 Version: 42.2-1+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Lucas Kanashiro Description: libyelp-dev - Library for the GNOME help browser (development) libyelp0 - Library for the GNOME help browser yelp - Help browser for GNOME Changes: yelp (42.2-1+deb12u1) bookworm-security; urgency=medium . * Non-maintainer upload by the Security Team. * Fix CVE-2025-3155. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. - d/p/CVE-2025-3155.patch Checksums-Sha1: fbf473fa049a3309a9d5d9abdec5469f09893bd9 75076 libyelp-dev_42.2-1+deb12u1_i386.deb 5a558729f24cb45637e0b5c5c1c6d51664fb774b 289028 libyelp0-dbgsym_42.2-1+deb12u1_i386.deb c25f20a88856a6613a0b3754c09b6f5e75d17c05 168168 libyelp0_42.2-1+deb12u1_i386.deb b41065e2b43a46fe45e7e064f2f289d3c309dcf6 54880 yelp-dbgsym_42.2-1+deb12u1_i386.deb a6326005ae1851b96f2304b2690b012e9e61949c 20837 yelp_42.2-1+deb12u1_i386-buildd.buildinfo d93de48bf46b732ddd9a0763dfbb0850692bbbc9 781456 yelp_42.2-1+deb12u1_i386.deb Checksums-Sha256: 37475cec7d61ad400075aa4310de052ed3cba59b01c7abe3fee06476955eb567 75076 libyelp-dev_42.2-1+deb12u1_i386.deb 90569257a1e07afeb54c7a8a00c24c7534b22d68d87bd883abecf3acb0b082b3 289028 libyelp0-dbgsym_42.2-1+deb12u1_i386.deb 4a5d03216809e32df6f5b33070346681d453f616b1923de664a7aa4e425bf5ad 168168 libyelp0_42.2-1+deb12u1_i386.deb 8fd983be85fa1a4871eef5cbc694dd80ecf2936da9ea481051cb5f80b4f2548a 54880 yelp-dbgsym_42.2-1+deb12u1_i386.deb 1b61f4f91031a418145407b5a3b101023f0df38c57452821cf9e607f35d42402 20837 yelp_42.2-1+deb12u1_i386-buildd.buildinfo ee8187963f243a83d5cb3392e0aa97ce37ef91486aef799d8417720b950314fa 781456 yelp_42.2-1+deb12u1_i386.deb Files: a95e6081e6ad0a7083dd3b323ff7a8b9 75076 libdevel optional libyelp-dev_42.2-1+deb12u1_i386.deb 19a9c3e1e60220bb5ccb680597d54120 289028 debug optional libyelp0-dbgsym_42.2-1+deb12u1_i386.deb 2acc77c6575931b8e4ecef861b57252e 168168 libs optional libyelp0_42.2-1+deb12u1_i386.deb 5d2207d0590e540d02b5a7ba0ecc9aa7 54880 debug optional yelp-dbgsym_42.2-1+deb12u1_i386.deb 496b5f3ef5ad42b2e41de1fff723ede8 20837 gnome optional yelp_42.2-1+deb12u1_i386-buildd.buildinfo 40a06dcb131a9548aeaa2fcce1478c5f 781456 gnome optional yelp_42.2-1+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErwLLVsiCiGZggzpHJuP6X4A0XeIFAmg0vtEACgkQJuP6X4A0 XeLWYg/+OvNjx1pnYh6gMMQ8RY5M4YTPXpAcwe6N8CfNs2jmUEHUHivNukZjS4yE ggCeOqLSH6l/fUPkRhvgJ9IDB9UucW/VG0U3Eu8/T1ySxIdVZ/lOqlATGDlh+RI3 5kvWQR2KpyLZnYop0E7w3C14xg/gaNdK8hRQE0ho1nhq9F8QHfOKyPjFQwjW3TIu dqt6zVBcH+MSi+667qN3OVTi/DZGQupgO6NB7eHq/pxHW/3LJDkJuLdkfi5lzNmy /vVNkcbBJiH85FTZqW2OBMqHw0fFpZxaMMf/1Rr1FfuT4L5q4mHrv9MiUsNzPIJQ uQDilOw+Zd2niopAnpSRNddDG9XoV8tx+pkbq7ZiBAxiNOsGrRSoqi112snPYG77 52rJDDxFzsOIfX2QMn/NaQr9jhfShqTn+CLj0Sc4LydsXQHgfM9v+qFbdzQ/MZre OXbTcBRTIGFiiNB6oiHqot+WJ9a1qF0foI8nhpmkK6zaJWbiuJH0aSwK1wNoTBRX GQhc3mdW2hne1pgFXlt8unYcheNfUQYdpuhUTt7Prw+hwRgqGdgG6vfRYJy8aPHt EikwzhZYFlExN8wkDRHWVgQpnvCRIwe3JeoyBtIKVRWaAXsRHtSfqz6/kTJrd6sN 2dHOSLVTU800PLVOSPsM36XFU2jMvuY6g3kbbjOn26ae6bvo4Fs= =GK3x -----END PGP SIGNATURE-----