Debian Patches
Status for yelp/42.2-4+deb13u1
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| disable_package_search.patch | Remove "Search for packages" 404 feature since it doesn't work with Debian's PackageKit. We apparently need to implement org.freedesktop.PackageKit.Modify.InstallProvideFiles https://wiki.debian.org/SessionInstaller =================================================================== |
Jeremy Bicha <jbicha@ubuntu.com> | not-needed | upstream | 2011-09-26 | |
| CVE-2025-3155.patch | Initial fix for CVE-2025-3155 from parrot409 use a nonce to prevent arbitrary script execution |
Shaun McCance <shaunm@gnome.org> | no | https://gitlab.gnome.org/GNOME/yelp/-/issues/221 | 2025-04-18 | |
| sandbox-escape-1-no-ghelp-proc.patch | Don't allow ghelp:/proc URIs When there is something you can exploit, this kind of URI is a way to trick people into running a malicious document. I doubt there are any legitimate use cases. This change mitigates risk. |
Shaun McCance <shaunm@redhat.com> | yes | debian upstream | upstream, https://gitlab.gnome.org/GNOME/yelp/-/commit/d220aa2f754eed4e6a006a4acaa68b31892dea2b | 2026-05-06 |
| sandbox-escape-2-no-external-resources.patch | Don't allow loading external resources from web pages This is an attack vector for sending data places. yelp-web-extension.c; upstream later renamed the directory to web-process-extension. The hunk is otherwise unchanged. |
Shaun McCance <shaunm@redhat.com> | yes | debian upstream | upstream, https://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639 | 2026-05-06 |
All known versions for source package 'yelp'
- 49.1-3 (sid, forky)
- 42.2-4+deb13u1 (trixie, trixie-security)
- 42.2-1+deb12u2 (bookworm-security, bookworm)
