UbuntuUpdates.org

Package "libyelp-dev"

Name: libyelp-dev

Description:

Library for the GNOME help browser (development)

Latest version: 42.2-2ubuntu0.1
Release: plucky (25.04)
Level: security
Repository: main
Head package: yelp
Homepage: https://wiki.gnome.org/Apps/Yelp

Links


Download "libyelp-dev"


Other versions of "libyelp-dev" in Plucky

Repository Area Version
base main 42.2-2
updates main 42.2-2ubuntu0.1
PPA: Mint Upstream 3.26.0-1ubuntu2mint1
PPA: Mint Upstream 3.26.0-1ubuntu2mint1

Changelog

Version: 42.2-2ubuntu0.1 2025-04-23 15:07:45 UTC

  yelp (42.2-2ubuntu0.1) plucky-security; urgency=medium

  * SECURITY UPDATE: arbitrary script execution
    - debian/patches/CVE-2025-3155.patch: use a nonce in
      data/xslt/mal2html.xsl.in, data/xslt/man2html.xsl.in,
      data/xslt/yelp-common.xsl.in, libyelp/yelp-transform.c,
      libyelp/yelp-view.c.
    - CVE-2025-3155

 -- Marc Deslauriers <email address hidden> Thu, 17 Apr 2025 10:42:31 -0400

CVE-2025-3155 A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious



About   -   Send Feedback to @ubuntu_updates