Debian alert DLA-4647-1 (yelp)
| From: | Daniel Leidert <dleidert@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4647-1] yelp security update | |
| Date: | Thu, 25 Jun 2026 01:40:23 +0200 | |
| Message-ID: | <210f504e559fc1cb8fa47cc2f6cbf7ac1f0e7781.camel@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4647-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Daniel Leidert June 25, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : yelp Version : 3.38.3-1+deb11u2 CVE ID : not assigned Debian Bug : 1136299 A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server through resources loaded by the embedded web view. When yelp is launched from a sandboxed application (for example via the Flatpak OpenURI portal), this also enables a sandbox escape. For Debian 11 bullseye, this problem has been fixed in version 3.38.3-1+deb11u2. We recommend that you upgrade your yelp packages. For the detailed security status of yelp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/yelp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmo8aucUHGRsZWlkZXJ0 QGRlYmlhbi5vcmcACgkQS80FZ8KW0F0NbA/7BIbh6wmvkDHswek/HkGW0sJtTg4S KAroXHAtc//ZTAor4ds2PgGwLFJVWWPIUVYdIa1ylesRvH4RplkgOe3KOeeYF9dA kt5/CoxPO1r/9sKoA4eLVvAXW1xciEjUugTXigFM44MfGymmkxKGqkMzulkq7jSJ pSlgSGat5EmtJKjH8QbDsaU9rxuTl9K1vnlrgyA2lHFGtl1TgcOQ1P1qqfLbeCyq clZnysT4koCmFJM8qGfGD0vIwRHvPBcNvLuujPyJGv0V34/5fZY7KQbfWHoSnpI9 4EpxHUK/kyoKOuYBWJhyDkrwRkLW2IvRFeSvB4XfAB+APRZHkOlJBrAuNw6UPpAD XARcNLCbr5gFz+BkVSg9Za6mxINzO965fSczs9d1G4W1SXJCHVMSJLfG8fSpFq7F 92V2xyxbpsSHI0C4kYcoyYAoXVhO7QnLjh30SyJ9FPKSESIrfiAvpvtsWbEKooC0 4ivPptjfvXIDJvT3lqBInQgrT4xE1+PRZjk/75MTceKeQOlptWYq1+nAiF1F6NhI wPcYuNhl2NQrozW2C3Dp0ntadSgFhurmdfN6Kij+sgzTWjRk0pP46PLqHZs1sLFF WN0eGzumlU2NNJB/0k5jow7tghHPwe7WqZhlbh0DYpE+E2NyP5do+QzfR18cPtgT /DDXpC8rbVKTE6U= =x/w5 -----END PGP SIGNATURE-----
