-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 23 Apr 2025 12:17:23 -0400 Source: yelp Built-For-Profiles: noudeb Architecture: source Version: 42.2-3 Distribution: unstable Urgency: high Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Jeremy Bícha <jbicha@ubuntu.com> Closes: 1102080 Changes: yelp (42.2-3) unstable; urgency=high . [ Marc Deslauriers ] * SECURITY UPDATE: arbitrary script execution - debian/patches/CVE-2025-3155.patch: use a nonce in data/xslt/mal2html.xsl.in, data/xslt/man2html.xsl.in, data/xslt/yelp-common.xsl.in, libyelp/yelp-transform.c, libyelp/yelp-view.c. - CVE-2025-3155 (Closes: #1102080) Checksums-Sha1: cc26a8ebda797382dab2c9ebf4ced3dced8002bf 2449 yelp_42.2-3.dsc 6658e4c049d1dc055adb25131007e83ac092d342 18420 yelp_42.2-3.debian.tar.xz 85f767f6f68bdaf83be5297bd2c9b817de8b571b 17927 yelp_42.2-3_source.buildinfo Checksums-Sha256: 895470600351a54f5fa746cdb75529570cf35eda1f85ab5dfc6450c79ff58885 2449 yelp_42.2-3.dsc 03835e6622ef2585939902e7604c5f7d28cb36530f653db680a71cb368890f92 18420 yelp_42.2-3.debian.tar.xz 25f3ded83ccd83667f948689a368b0372177cdb92ff9a82fb12a4c5b36f1424b 17927 yelp_42.2-3_source.buildinfo Files: 84498b92ca54cc15a2f8030e0039c09d 2449 gnome optional yelp_42.2-3.dsc 3b6160c46ac2a837ed008c1f49ac6669 18420 gnome optional yelp_42.2-3.debian.tar.xz 5cbc67728ba34bd659b1f47bc3327370 17927 gnome optional yelp_42.2-3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmgJEsUACgkQ5mx3Wuv+ bH3RMQ/+KWA+I8LZDNJLogfDOTIPon4LejcCON5/CpnClx8kjhFrluCiJXzKShO2 Tsd57TlXHBOYhR28x8EKi/jhCoHWFsO2tuCeTOsHBhnZ1s6jDY/8MEu96bC0U8t1 XXqS468J+/0o5g/av7+mrVN9j4lCQWRTQokk7fVtvBXsgEtn83UotbFhMMQxASgG wH2oVFxrhruwPdkRn+Ih4HWEiYape2YjB6VtnF/WfPjTkcLnyzd9pAaCBNKMrbVs JazQAguR2vFlwDFlyfP4nS1eADGYW0RLxpDb2UG8xTFt0UmU/j6/uhf5q+wKxeT7 y3mH+5MU1m+jbi2MLJGVXODIr1yxxi9uKVQRVJ4QrYzPPtmyPhLfINOVDhLY5Xez omN9aNIxj9B8dT32S4/K/Z0qvok9Un9B6KzGfa+aExK5i2rIdj8y8IgMIvlj2tuy gYhn5VKbJ6uEZtdf8mKOyC3S5QspuazWu/EGQ0HJajU/8NLdkCMZXzfuzcapK297 X9hPRoWujiqYwvUhfvwGGM1RRlsebfxPF6/ATrARkJSuQodtk/6X4+3VsCSpj10a lmauc3+LoSRrUWVklOu5deixQSiDDgaC5AxN1g0EcUDz2Ky41S30KGhyOf7hjUi1 59RFfQyqka/EZohYCMTaBFPOg2uylwFPGO0qarRQRXhKW5pIxHU= =DGk2 -----END PGP SIGNATURE-----