-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 May 2026 23:30:00 +0000 Source: yelp Binary: libyelp-dev libyelp0 libyelp0-dbgsym yelp yelp-dbgsym Architecture: amd64 Version: 42.2-1+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Aron Malache Description: libyelp-dev - Library for the GNOME help browser (development) libyelp0 - Library for the GNOME help browser yelp - Help browser for GNOME Closes: 1136299 Changes: yelp (42.2-1+deb12u2) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * SECURITY UPDATE: sandbox escape via ghelp: URIs and external resources loaded by help pages, allowing a malicious help document to read arbitrary files (e.g. via /proc) and exfiltrate them over the network (Closes: #1136299). Checksums-Sha1: 521862a68533d0bec8324473d8a15d615c86e5ae 75268 libyelp-dev_42.2-1+deb12u2_amd64.deb 6f0d0d13714e032dace5e9d00aec626fc97949de 340940 libyelp0-dbgsym_42.2-1+deb12u2_amd64.deb 1e4bbf0c2667a407c3d29192f3c6806a456e4ae6 159036 libyelp0_42.2-1+deb12u2_amd64.deb c9ec69ef1817359c34ba768553f02c8b97f6c691 63672 yelp-dbgsym_42.2-1+deb12u2_amd64.deb 88e1e3b721b81adde2fb6d1c46b3652b2170cec3 20839 yelp_42.2-1+deb12u2_amd64-buildd.buildinfo 09fb35730c0e7ed9856590dcc1d75b31bd557469 779800 yelp_42.2-1+deb12u2_amd64.deb Checksums-Sha256: c46760de4350f738211e7a9ab9117749883e44a786214f3cabe335d40c7e9799 75268 libyelp-dev_42.2-1+deb12u2_amd64.deb 9e20ffc10e828178e91f89ccd7aac13a2590f3b84a38b70c0cfb3a6dadcbad14 340940 libyelp0-dbgsym_42.2-1+deb12u2_amd64.deb 3a87b942c0a49738b6954002240ad6fa696e47eca99bf956609078ff986e91f3 159036 libyelp0_42.2-1+deb12u2_amd64.deb fd90f330f060cdba476bb4b83b8341ef9ccdba377d2a6c7dba43e8f2a93ead6b 63672 yelp-dbgsym_42.2-1+deb12u2_amd64.deb c9b031f6c9d41ceb06d3bfa90cb3967beec4d3fb52c99415d98f6569d2124a89 20839 yelp_42.2-1+deb12u2_amd64-buildd.buildinfo 2c86938397f78be6947a13b992bcc21ac61735c3523e94b51ad2bb40bf930ee0 779800 yelp_42.2-1+deb12u2_amd64.deb Files: 9612a9ba76f042ffdb7d63d6686af499 75268 libdevel optional libyelp-dev_42.2-1+deb12u2_amd64.deb ab0d8230d9dca74b5fb7b3749ffd723c 340940 debug optional libyelp0-dbgsym_42.2-1+deb12u2_amd64.deb 9c17fff8a9a3b5438cdff44cbd0fde34 159036 libs optional libyelp0_42.2-1+deb12u2_amd64.deb c15c55ca6fd8a528bbb55d2604d99ef6 63672 debug optional yelp-dbgsym_42.2-1+deb12u2_amd64.deb 0867b33dc43b94b137675c36d2d444be 20839 gnome optional yelp_42.2-1+deb12u2_amd64-buildd.buildinfo bb85a1edf6b0debf146432b3a4c2315e 779800 gnome optional yelp_42.2-1+deb12u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmodRNwACgkQN8Ugyu9d QiS4JBAAmDsVefvhYwaeP43kv4tX6rS9KUkRJlIMECCe/uXLBa/KIqn9YmpT6ufN Ls1EfN6Wlnw4pNbrZ+bS2FrG0EGH9TPl06D19vlcQitFzP9/Wg2izKy6hE109lG9 /nnGkavD+vKyoQ6eOJl1wNf6dl71b8zzwVwUhc4s1PzdkQv1sR7meX4octx54G0F y6zxBoXyHBiBeFtisILdE6Xw0aWm4lFbw98iHKOPo/84zygb+bqofMDz8AwIZXXw wH0Y4EyYCFsi6OJEuJB49ZKXZ6TWsnCARfv8ZWx0RmCQdwN717PsnrqndIygRsAZ F52vaXDl8mDFI+WEiFMl5isT8uBdQhPSmDcpm3sn2SO8l3mS9OM5EY1Ntw/qSQd0 YSOO73kh0vGEmDgNTRtW47Y31soagBUoD+q1keCI6MfPw0liuxNBRlVDJpXr3TGh 6w0oxATAFAvPWCny1F9s5iigPqYgWCZeKo8lSRR+hMpavl7w6vhUSHP+v/Cv6b7V AO9n2zZMIn7QVwGP3WpLWFRLQeOKjSMPpK6Ti1Q7Si6/5u3/86Dc1ns5hQrrb0O4 9XVVBz1mnjwmoI8KZDo3yyWLOH6zx2DsdQxsivpHvASR4nv7YeGjr2IKmPvDZGHg uleXBgwkUqsYBnHlo3vetPb0KhbqwE+gR4eVCIReycoB+Ysla3Q= =wIeY -----END PGP SIGNATURE-----