MGASA-2025-0297 - Updated yelp & yelp-xsl packages fix security vulnerability. MGASA-2025-0297 - Updated yelp & yelp-xsl packages fix security vulnerability Publication date: 15 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0297.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-3155 Description: The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. (CVE-2025-3155) References: - https://bugs.mageia.org/show_bug.cgi?id=34173 - https://www.openwall.com/lists/oss-security/2025/04/04/1 - https://lists.fedoraproject.org/archives/list/
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4184-1
Get the latest Linux and open source security news straight to your inbox.