Alerts This Week
Warning Icon 1 1,039
Alerts This Week
Warning Icon 1 1,039

Debian LTS Yelp Serious Data Exfiltration Threat DLA-4647-1

debian lts
Calendar Grey June 24, 2026
Dist Debian Esm H88
Explore the critical security update for Yelp addressing a file read and exfiltration vulnerability present in Debian LTS.
A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server thro...

Summary

For Debian 11 bullseye, this problem has been fixed in version
3.38.3-1+deb11u2.

We recommend that you upgrade your yelp packages.

For the detailed security status of yelp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/yelp

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: yelp
Version: 3.38.3-1+deb11u2
CVE ID: not assigned
Debian Bug: 1136299

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here