-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 26 May 2025 16:28:15 -0300 Source: yelp Architecture: source Version: 3.38.3-1+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Lucas Kanashiro <kanashiro@debian.org> Changes: yelp (3.38.3-1+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS team. * Fix CVE-2025-3155. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. - d/p/CVE-2025-3155.patch Checksums-Sha1: e156194c43a2c3324ef260cef306b3e8c789007c 2553 yelp_3.38.3-1+deb11u1.dsc 5b8c4f11e7abed2bb140dece5942b241af8ab73f 1505460 yelp_3.38.3.orig.tar.xz 7fb583621cab826057269951d071f0c3eb0d8900 18864 yelp_3.38.3-1+deb11u1.debian.tar.xz Checksums-Sha256: 82ad156813af8ba288dc455c2f411994357d164cb90bf86d39da2cb9fa23b2c5 2553 yelp_3.38.3-1+deb11u1.dsc afd46a4d0aeb46bb425c520071d818f8b2b32e69e756abfd997968769a61549d 1505460 yelp_3.38.3.orig.tar.xz e7ad1445de1900d9307f70b0c7293786a5835078490e21d65de8d1ffc3465e6d 18864 yelp_3.38.3-1+deb11u1.debian.tar.xz Files: 6440182122d200c44ffa726f54e466a2 2553 gnome optional yelp_3.38.3-1+deb11u1.dsc 33c319da0f332b535758a5d7b7a138ad 1505460 gnome optional yelp_3.38.3.orig.tar.xz 52fd3722972109b087aa6bb46601d66a 18864 gnome optional yelp_3.38.3-1+deb11u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQJJBAEBCgAzFiEEjtbD+LrJ23/BMKhw+COicpiDyXwFAmg3TTEVHGthbmFzaGly b0BkZWJpYW4ub3JnAAoJEPgjonKYg8l8FGgP/jXBtvKWYhz6TD9Ra8gJNOwVWEUh eJ62gLKOzkxCdcYYVzIfORSvZI6Ow9fXE8NPneVMr6CpXcQtNuCrgO/ItE7o2xoa NaNtVpdzX32E8cQwm2IDCflMMLgmjG8oEU3//t5j4bGIzFnARQlA6vRP0za/mD58 7a2onspcnsU7UNQhifrrBUCFMgUDXWFt1fmu4UAp0vpLsjDqSyuYGC/Xm4IrPHKo PbBaaMS9FNdyLUNRFOuQ2F6vBnaH6tv7YeGTzWpvlxXJBKy5DLmJ7UcaoywrTP+m vcLHx4Vv8p0YgVRKvlq37Sto9eENTYya7q9nc8xIew52ZkqDfHjUIY0UzwrCkrDf rxsHfxXGBizESswLRRaymHS2VFBcHn9BHsiPs8ak3qAKQnvVvL8t/IOu7yVjFdbd z+Xb6Z1py0+FItSu2ISefADflaKyZkWSWP/rqZjeL6vkEGRDIXTSB5218OIssxcE GSDsYn0yZWUjERqeoUpQnqRfUyjxYRIH7AMWyMhiG2Fr6QeRLrtAkb+7je9VISxE hrkGp3LEJXbd3wEoebNuO4KCAbDTQDf/CEmmaZ2W71V/T9at4axljItCOpqFvz9w 7HGZKY528uTavrNSJtrX3kfeDw1A6/1NZfGwzlmc0iznOwJ7ILDRtvIdJTzJt1yV m4gRIl/7sM9MbDhB =LUyJ -----END PGP SIGNATURE-----