Debian Patches

Status for yelp/42.2-4+deb13u1

Patch Description Author Forwarded Bugs Origin Last update
disable_package_search.patch Remove "Search for packages" 404 feature
since it doesn't work with Debian's PackageKit. We apparently
need to implement org.freedesktop.PackageKit.Modify.InstallProvideFiles

https://wiki.debian.org/SessionInstaller

===================================================================
Jeremy Bicha <jbicha@ubuntu.com> not-needed upstream 2011-09-26
CVE-2025-3155.patch Initial fix for CVE-2025-3155 from parrot409
use a nonce to prevent arbitrary script execution
Shaun McCance <shaunm@gnome.org> no https://gitlab.gnome.org/GNOME/yelp/-/issues/221 2025-04-18
sandbox-escape-1-no-ghelp-proc.patch Don't allow ghelp:/proc URIs
When there is something you can exploit, this kind of URI is a way
to trick people into running a malicious document. I doubt there
are any legitimate use cases. This change mitigates risk.
Shaun McCance <shaunm@redhat.com> yes debian upstream upstream, https://gitlab.gnome.org/GNOME/yelp/-/commit/d220aa2f754eed4e6a006a4acaa68b31892dea2b 2026-05-06
sandbox-escape-2-no-external-resources.patch Don't allow loading external resources from web pages
This is an attack vector for sending data places.


yelp-web-extension.c; upstream later renamed the directory to
web-process-extension. The hunk is otherwise unchanged.
Shaun McCance <shaunm@redhat.com> yes debian upstream upstream, https://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639 2026-05-06

All known versions for source package 'yelp'

Links