Exposure of Sensitive System Information to an Unauthorized Control Sphere in Yelp - CVE-2025-3155
Published: April 23, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the way Yelp handles JavaScript content. A remote attacker can trick the victim into opening a specially crafted file and exfiltrate sensitive information by forcing Yelp to share contents of arbitrary files to a third-party remote server.
Affected software
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openSUSE Leap
openEuler
Ubuntu
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
yelp-lang
yelp
yelp-debuginfo
yelp-devel
yelp-debugsource
libyelp0
libyelp0-debuginfo
yelp-xsl (Red Hat package)
yelp (Red Hat package)
yelp-xsl (Ubuntu package)
yelp-help
yelp-xsl
yelp-xsl-devel
yelp-xsl-help
yelp (Ubuntu package)
yelp-libs
yelp (Debian package)
yelp-doc
How to mitigate CVE-2025-3155
yelp - addressed in versions 3.20.1-7.3.1, 41.2-150400.3.3.1
yelp-debuginfo - addressed in versions 3.20.1-7.3.1, 41.2-150400.3.3.1
yelp-devel - addressed in versions 3.20.1-7.3.1, 41.2-150400.3.3.1
yelp-debugsource - addressed in versions 3.20.1-7.3.1, 41.2-150400.3.3.1
libyelp0 - addressed in versions 3.20.1-7.3.1, 41.2-150400.3.3.1
libyelp0-debuginfo - addressed in versions 3.20.1-7.3.1, 41.2-150400.3.3.1
yelp-xsl (Red Hat package) - update to 3.28.0-2.el8_10.1
yelp (Red Hat package) - addressed in versions 3.28.1-3.el8_2.1, 3.28.1-3.el8_4.1, 3.28.1-3.el8_6.1, 3.28.1-3.el8_8.1, 3.28.1-3.el8_10.1, 40.3-2.el9_0.1, 40.3-2.el9_2.1, 40.3-2.el9_4.1, 40.3-2.el9_6.1
yelp-xsl (Ubuntu package) - addressed in versions 3.36.0-1ubuntu0.1, 42.0-1ubuntu0.1, 42.1-2ubuntu0.24.04.1, 42.1-2ubuntu0.24.10.1, 42.1-3ubuntu0.1
yelp - addressed in versions 3.36.0-2, 3.38.3-2, 42.2-3
yelp-help - addressed in versions 3.36.0-2, 3.38.3-2
yelp-devel - addressed in versions 3.36.0-2, 3.38.3-2, 42.2-3
yelp-xsl - update to 3.36.0-2
yelp-xsl-devel - update to 3.36.0-2
yelp-xsl-help - update to 3.36.0-2
yelp-debugsource - addressed in versions 3.36.0-2, 3.38.3-2, 42.2-3
yelp-debuginfo - addressed in versions 3.36.0-2, 3.38.3-2, 42.2-3
yelp (Ubuntu package) - addressed in versions 3.36.2-0ubuntu1.1, 42.1-1ubuntu0.1, 42.2-1ubuntu0.24.04.1, 42.2-1ubuntu0.24.10.1, 42.2-2ubuntu0.1
yelp-libs - addressed in versions 40.3-2, 42.2-4
yelp - addressed in versions 40.3-2, 42.2-4
yelp-devel - addressed in versions 40.3-2, 42.2-4
yelp (Debian package) - update to 42.2-1+deb12u1
yelp-doc - update to 42.2-4
yelp - addressed in versions 42.2-9.fc40, 42.2-9.fc41, 42.2-9.fc42
External References
Related Security Bulletins
- Information disclosure in Gnome Yelp
- Ubuntu update for yelp
- Red Hat Enterprise Linux 9 update for yelp
- Red Hat Enterprise Linux 8 update for yelp
- Red Hat Enterprise Linux 8 update for yelp
- Red Hat Enterprise Linux 9 update for yelp
- Red Hat Enterprise Linux 8 update for yelp
- Red Hat Enterprise Linux 9 update for yelp
- Red Hat Enterprise Linux 8 update for yelp
- Fedora 40 update for yelp
- Fedora 42 update for yelp
- Fedora 41 update for yelp
- Red Hat Enterprise Linux 9 update for yelp
- Red Hat Enterprise Linux 8 update for yelp and yelp-xsl
- openEuler update for yelp-xsl
- openEuler 24.03 LTS SP1 update for yelp
- Anolis OS update for yelp
- Debian update for yelp
- openEuler 22.03 LTS SP3 update for yelp
- openEuler 20.03 LTS SP4 update for yelp
- openEuler 24.03 LTS update for yelp
- openEuler 22.03 LTS SP4 update for yelp
- SUSE update for yelp
- Anolis OS update for yelp
- SUSE update for yelp