GNOME has issued CVE-2025-3155 for the following bug in Yelp, the help file
viewer in the GNOME Desktop (unrelated to the similarly named app for
restaurant reviews):

   https://gitlab.gnome.org/GNOME/yelp/-/issues/221

The description they landed on after analysis was:

   Yelp, the GNOME user help application, allows help documents to execute
   arbitrary JavaScript. A malicious help document may exfiltrate user files
   to a remote server. A malicious website may download a help document
   without user intervention, then trick the user into opening a ghelp URL
   that references the help document. This notably requires the attacker to
   guess the filesystem path of the downloaded help document.

While there are proposed patches in the bug report, none seem to have been
committed to the git repo yet.

--
        -Alan Coopersmith-                 alan.coopersm...@oracle.com
         Oracle Solaris Engineering - https://blogs.oracle.com/solaris

Reply via email to