-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 May 2026 23:30:00 +0000 Source: yelp Architecture: source Version: 42.2-4+deb13u1 Distribution: trixie-security Urgency: high Maintainer: Debian GNOME Maintainers Changed-By: Aron Xu Closes: 1136299 Changes: yelp (42.2-4+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * sandbox escape via ghelp: URIs loaded by help pages, allowing a malicious help document to read arbitrary files (e.g. via /proc) and exfiltrate them over the network (Closes: #1136299). Checksums-Sha1: 3d8b15bca2ee5cd4dc95b45b826a03c772240a80 2132 yelp_42.2-4+deb13u1.dsc de1d6d374bfd34b2519f1722f0887831ce176b1a 1480504 yelp_42.2.orig.tar.xz fcd0ab436bf54ecf6b0e6dc225c5ca690b61e7d6 19404 yelp_42.2-4+deb13u1.debian.tar.xz ac1049945ea9761415fd0750448c53098e2a18f5 7347 yelp_42.2-4+deb13u1_source.buildinfo Checksums-Sha256: 8bc4ecaeba075e5a97b713eb2525aee0318b69043e7df8ad4aaed8b31bc32475 2132 yelp_42.2-4+deb13u1.dsc b29e9512766bcd684bdc650457e4ecc99b236935c2c16d2acd4f7dd2cfc87a2e 1480504 yelp_42.2.orig.tar.xz f0ed9a7da47e822daef2f3f7ff410aeeb399398036fb7069d93c6d6973f30881 19404 yelp_42.2-4+deb13u1.debian.tar.xz ecdf25bd228df21d59a9dda2650b9a8e65921f8c533da45c855f17ba8fb08a29 7347 yelp_42.2-4+deb13u1_source.buildinfo Files: bc2096e1dab542e0a4bab82db19c464a 2132 gnome optional yelp_42.2-4+deb13u1.dsc 520c1e430279df7a7100164a80791280 1480504 gnome optional yelp_42.2.orig.tar.xz cdcf4d137b35c7ca02330e4edd051dbc 19404 gnome optional yelp_42.2-4+deb13u1.debian.tar.xz baa2ce6da2ff6fa707fcf5f7e380e164 7347 gnome optional yelp_42.2-4+deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmodPwQACgkQ+GQ1dHE8 m652gQgA5R00CnyxgQG1zgUKqXLXvOoxTLTDQpDrgzzuRLgwM0C4zc/4lXaogmqV daZq4msoUumQGAgLdsStTCLhozCsOYaXfP4MB6Ox7h1pBAFJ8F73RjGTB0cHedd9 E5zvVDA1zc6ive5o2oVp3x5Ay7bNXr05RxkCKuF6UjyT5vKT0OQGEzIL4lA0ADQE /Wmt1CqmkV/PB8aIEzpaPov0aQ9HPhayJPZsWWpcQlcXeBs0WFujPuY+j9U6MFz8 IjBo+A1TwYYRfw/kDyYijYEsX8KaOVdir+gud1NPXYZaFZii2RLMsNvn/vjiQEsy x02SlfK0V5cLx2qKdl0ONXKlfZHLoA== =sI7O -----END PGP SIGNATURE-----