PT-2025-14719 · Yelp+11 · Yelp+11

Parrot409

·

Published

2024-12-25

·

Updated

2026-05-17

·

CVE-2025-3155

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yelp versions prior to 42.2 Yelp versions prior to 3.38.3-1+deb11u1 Yelp versions prior to 3.36.2-0ubuntu1.1 Yelp-xsl versions prior to 42.1-2+deb12u1 Yelp-xsl versions prior to 3.36.0-1ubuntu0.1
Description A flaw in the Gnome user help application allows help documents to execute arbitrary scripts. This issue stems from the incorrect handling of paths in ghelp URLs and the inclusion of functions from an untrusted controlled area when processing documents using the ghelp scheme. A remote attacker can exploit this by tricking a user into opening a specially crafted help file, which may lead to arbitrary code execution and the exfiltration of sensitive user files, such as SSH keys, to an external environment.
Recommendations Update to version 42.2 or later. Update to version 3.38.3-1+deb11u1. Update to version 3.36.2-0ubuntu1.1. Update yelp-xsl to version 42.1-2+deb12u1. Update yelp-xsl to version 3.36.0-1ubuntu0.1.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALSA-2025:7430
ALSA-2025:7569
ALT-PU-2025-8113
ALT-PU-2025-8115
BDU:2025-03944
CESA-2025_7569
CVE-2025-3155
DLA-4184-1
DLA-4185-1
DSA-5927-1
INFSA-2025_7430
INFSA-2025_7569
MGASA-2025-0297
OESA-2025-1535
OESA-2025-1543
OESA-2025-1606
OESA-2025-1607
OESA-2025-1608
OESA-2025-1609
OPENSUSE-SU-2025:15167-1
OPENSUSE-SU-2025:15168-1
RHSA-2025:4450
RHSA-2025:4451
RHSA-2025:4455
RHSA-2025:4456
RHSA-2025:4457
RHSA-2025:4505
RHSA-2025:4532
RHSA-2025:7430
RHSA-2025:7569
RHSA-2025_7430
RHSA-2025_7569
SUSE-SU-2025:01904-1
SUSE-SU-2025:02153-1
SUSE-SU-2025:02168-1
SUSE-SU-2025:02169-1
SUSE-SU-2025:02170-1
SUSE-SU-2025:2169-1
SUSE-SU-2025_02153-1
SUSE-SU-2025_02168-1
SUSE-SU-2025_02169-1
SUSE-SU-2025_02170-1
SUSE-SU-2025_2169-1
USN-7447-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Yelp