security advisoryDebianmalicious input
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4185-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Lucas Kanashiro May 28, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : yelp-xsl Version : 3.38.3-1+deb11u1 CVE ID : CVE-2025-3155 Debian Bug : #1102080 A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. For Debian 11 bullseye, this problem has been fixed in version 3.38.3-1+deb11u1. We recommend that you upgrade your yelp-xsl packages. For the detailed security status of yelp-xsl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/yelp-xsl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An important patch for yelp-xsl addresses a vulnerability that permits the running of scripts capable of leaking user data.. debian security update,yelp-xsl exploit,arbitrary script bug. . Severity: Critical. LinuxSecurity.com Team
May 28, 2025
•Critical
Debian LTS