Re: [BLFS Trac] #23258: yelp-49.1
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23258: yelp-49.1
-------------------------+------------------------------
Reporter: Bruce Dubbs | Owner: Douglas R. Reno
Type: enhancement | Status: assigned
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------------
Changes (by Douglas R. Reno):
* priority: normal => elevated
Comment:
{{{
49.1
====
* Fixed issue that could allow remoate access to local files
* Updated translations:
}}}
This contains a fix for
https://gitlab.gnome.org/GNOME/yelp/-/work_items/238 - which allows for
remote data exfiltration via malicious help files. Additional details in
https://blogs.gnome.org/mcatanzaro/2026/05/11/flatpak-sandbox-escape-via-
yelp/ - and unfortunately no CVE has been assigned still a month later.
The mention of Flatpak here doesn't mean much since non-sandboxed
applications can abuse this to retrieve data anyway through the same
attack vector utilizing the OpenURI portal. This is a repeat of
https://gitlab.gnome.org/GNOME/yelp/-/work_items/221
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23258#comment:6>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page