-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 May 2026 23:30:00 +0000 Source: yelp Binary: libyelp-dev libyelp0 libyelp0-dbgsym yelp yelp-dbgsym Architecture: i386 Version: 42.2-4+deb13u1 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Aron Xu Description: libyelp-dev - Library for the GNOME help browser (development) libyelp0 - Library for the GNOME help browser yelp - Help browser for GNOME Closes: 1136299 Changes: yelp (42.2-4+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * sandbox escape via ghelp: URIs loaded by help pages, allowing a malicious help document to read arbitrary files (e.g. via /proc) and exfiltrate them over the network (Closes: #1136299). Checksums-Sha1: f11b34a8c2f6600f5164850d65d0ae94760bd649 75348 libyelp-dev_42.2-4+deb13u1_i386.deb 862b5669c0aa38776a544fb74b479651cc8c5335 334324 libyelp0-dbgsym_42.2-4+deb13u1_i386.deb d104963c9a5a750634c604730b85a93cc1258eaa 169864 libyelp0_42.2-4+deb13u1_i386.deb 8cc5152679290ee6460b7f092d06e0403fb64dd8 53916 yelp-dbgsym_42.2-4+deb13u1_i386.deb a77ffbf91c257db81c8c30b39fc4734f26cf1e51 20034 yelp_42.2-4+deb13u1_i386-buildd.buildinfo 2d9b21c1a724a283a3de67164a015446ecf7404b 779752 yelp_42.2-4+deb13u1_i386.deb Checksums-Sha256: 1ce62ace14aeee906f465097f03143837fd6a6750853019a4c9b93f28337d905 75348 libyelp-dev_42.2-4+deb13u1_i386.deb 22c33eaf6f782dfe2443b175614fda8b63268963ce6b2bc22089b7dcdd5802a0 334324 libyelp0-dbgsym_42.2-4+deb13u1_i386.deb f6b2fceda73ee2a988a7cfd0523423e8ee0e98579ea92df665585fd7ff780b23 169864 libyelp0_42.2-4+deb13u1_i386.deb 97d1873bfdfb16aaf089c7a7acfe814897235e6f20d5c18372c87b884cacb90f 53916 yelp-dbgsym_42.2-4+deb13u1_i386.deb 93245f115c0ce50617c34b7f9f7e105ec58a2d80bdaf5536b115fd1c29ec2eba 20034 yelp_42.2-4+deb13u1_i386-buildd.buildinfo 42f9780801892c6de3eb9411038ddbbe68b0692d1b9bf74122ed16acbe7ca2f1 779752 yelp_42.2-4+deb13u1_i386.deb Files: c83c50f33998905696b8cc82724eaf6f 75348 libdevel optional libyelp-dev_42.2-4+deb13u1_i386.deb 5823bae575e02a02c6ea0d47153427d2 334324 debug optional libyelp0-dbgsym_42.2-4+deb13u1_i386.deb abde00b5d8d216b91d3d34a1ce9daf86 169864 libs optional libyelp0_42.2-4+deb13u1_i386.deb 73e75ccafca63b6a68efbd78e11c8087 53916 debug optional yelp-dbgsym_42.2-4+deb13u1_i386.deb 4186c294edc6c5d72a945310aac2406a 20034 gnome optional yelp_42.2-4+deb13u1_i386-buildd.buildinfo ecf1ab2c84e0056611beaa26358e29f3 779752 gnome optional yelp_42.2-4+deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+i/sCsF3puL4e7qIGNGWmfrqILEFAmodRR4ACgkQGNGWmfrq ILFe3g//ddxxgxRD8nrT+r8E/5MvLiSLbnW2pii4MqHBkVu3r1FwuSayTIs58gBT DZY7vFSIs1OzXW88EM/igE7mxX7GfywdD9O7Ph5RcnSuaObqG+f09qMhBVr2SYm3 mieyZKl3OJwIXcYgrq/Vs4GCgFVdooF2PXhdjyvVonviz8EgvwQNf9z9qPbct9j7 NnCMbvDxcbUInaFrd7fEEC4fJQe+s9nCQkMisIrBJKNJGbHbuxTmVg/FnMLNBPxi Ysfnubha31TjJhFeof029K96RzfCLbCI1qZP8c1uGzxm53DxmDd7+2dkBB1Wzyu7 C6yVOHpumZ4/Zu32xkRK2HxoZE/JiNmkrOsBpUwjtjVnWPhuBZFNWyeAbYBTPoKr miT6macmZ1Ae/CY63gPA0d0U8WcxCtDtgM+GQ/Qjv5pBOkrlOfF4t3ZT05YaIBVS I+fsk8Tkyp9UEVO529I3DN4gweCQefY8qKl5yOUJEEuhmdTwWBXj5/E2ME2v2wps rTVj9tc1VsIxzw4MyAS+d7ulwfBzj+ylHEdgzGADD0nYHl52trsHb85gsyJD3h/P 2qj9EXA5kuQ9nhRxqevfVTWZk0SjeOTfHoGtF9eRHsaAPQPoNpAWXnDj76vOq0Hj wxJEOMxJLMGdPbQQif7yRFLhy8Lnl5zzDoG00Ca87v0mm+YnrUk= =AQ4k -----END PGP SIGNATURE-----