[From nobody Tue Jun  2 19:49:04 2026
Received: (at 1136299-close) by bugs.debian.org; 2 Jun 2026 18:47:56 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-112.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,
 FREEMAIL_FORGED_REPLYTO,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,
 PGPSIGNATURE,SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 75; hammy, 150; neutral, 140; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:40030)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wUU9c-00AgVZ-0D for 1136299-close@bugs.debian.org;
 Tue, 02 Jun 2026 18:47:56 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mailly.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wUU9a-004FH0-2T for 1136299-close@bugs.debian.org;
 Tue, 02 Jun 2026 18:47:54 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=OZXQ6vESipENl6m/0Z0Tnm3J6Yns0KPQZybe9FtZk50=; b=k+9XSnmiJERyCy7j5ALTDH5M+i
 VJ29DU6H/x+iJTNWeEBKumc3Ovj9N3azVTEKKp/tUxAA7F1Cnrv874E/EbPYSzbwIOiYIh9Or8CYO
 S6YnS/qIvW3zSALQDuLqLoD1KdPmo7SrHWeCNxgWiAubwe7NJHvPDI2WygDfXbH6EI8adw/MmPJCj
 nhkXo1FI1bzPp57o25Lm0CW0zn/3r2+ClQeibSjhiVX2lKMxIGF197jFHYUjy8C0miQhJKwhtbLqp
 xiSuVbVK/cD5Y4Uot8FAW5JDKLKw4fazDU80r97v/hnSRZ6Amo8Etlb+HJw9LjWlhqOGicTWa9fWc
 bf6xzzsQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wUU9Z-00000005wq6-3eKI; Tue, 02 Jun 2026 18:47:53 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Aron Malache &lt;aronmalache@gmail.com&gt;
To: 1136299-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: yelp
Debian: DAK
Debian-Changes: yelp_42.2-1+deb12u2_source.changes
Debian-Source: yelp
Debian-Version: 42.2-1+deb12u2
Debian-Architecture: source
Debian-Suite: oldstable-proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1136299: fixed in yelp 42.2-1+deb12u2
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============6565860784301590863==&quot;
Message-Id: &lt;E1wUU9Z-00000005wq6-3eKI@fasolo.debian.org&gt;
Date: Tue, 02 Jun 2026 18:47:53 +0000

--===============6565860784301590863==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: yelp
Source-Version: 42.2-1+deb12u2
Done: Aron Malache &lt;aronmalache@gmail.com&gt;

We believe that the bug you reported is fixed in the latest version of
yelp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1136299@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aron Malache &lt;aronmalache@gmail.com&gt; (supplier of updated yelp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 28 May 2026 23:30:00 +0000
Source: yelp
Architecture: source
Version: 42.2-1+deb12u2
Distribution: bookworm-security
Urgency: high
Maintainer: Debian GNOME Maintainers &lt;pkg-gnome-maintainers@lists.alioth.debi=
an.org&gt;
Changed-By: Aron Malache &lt;aronmalache@gmail.com&gt;
Closes: 1136299
Changes:
 yelp (42.2-1+deb12u2) bookworm-security; urgency=3Dhigh
 .
   * Non-maintainer upload by the Security Team.
   * SECURITY UPDATE: sandbox escape via ghelp: URIs and external resources
     loaded by help pages, allowing a malicious help document to read
     arbitrary files (e.g. via /proc) and exfiltrate them over the network
     (Closes: #1136299).
Checksums-Sha1:
 3fd52428a767a8e978df5cd7b27ba9db413b5cb2 2135 yelp_42.2-1+deb12u2.dsc
 a42a021667352b31a230e1b47b4b4566a43e5953 19560 yelp_42.2-1+deb12u2.debian.ta=
r.xz
 78ee77e9526c8847d9fa856d9cb44d5a914ecfae 7347 yelp_42.2-1+deb12u2_source.bui=
ldinfo
Checksums-Sha256:
 41aca16ce9c3ecb9cd24419dd9ed23aba87e5994398a7fc44fd24a119084f0ba 2135 yelp_4=
2.2-1+deb12u2.dsc
 ecd450cebece67043088163f17205fc9c23145c701b705533535076ee89ff001 19560 yelp_=
42.2-1+deb12u2.debian.tar.xz
 1bee1115a850fb1a06443253f3e4d14f74491626cc5664aaa3fde9d980ef5fc9 7347 yelp_4=
2.2-1+deb12u2_source.buildinfo
Files:
 8836bcf03922f976cd08e0ed27ffba32 2135 gnome optional yelp_42.2-1+deb12u2.dsc
 c48044c1bb213fc808aff94467bf9d30 19560 gnome optional yelp_42.2-1+deb12u2.de=
bian.tar.xz
 59061abeca464600a7860e78db388324 7347 gnome optional yelp_42.2-1+deb12u2_sou=
rce.buildinfo

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmodPuYACgkQ+GQ1dHE8
m66TXwf+NcwScSm2t6l+qwE7SgIBZWiQFX9NXcuH/BxEPq8cxFvntDMvf6AdNVRQ
ghgGsZvDCLoFkbjt1RLSuGnZhyfiO1pVMVnbF3r+9az0uJisykcy1b5V49cCgVg7
+bI5e5ugSa1siAkz/3HbuC4P+ruyoEKG9fZgzKFOy2uFLNJRzTcdw2Fk9ZXfWXrb
ky3yJGAkCKMqDIFvKZvNUuXiPUuyEK1fMLMfuwI1EyTAhNmn/w2kecBo5vCaxcRh
W0n+hjbOhfaC5ozzyf+oiKIin9m3Ik71+blO4rvp6or2XR+bRjD6nEQ6bIBoUx+y
znHZ4Y9v/amalK8vivXvzoxmn85yTw=3D=3D
=3DrnQ8
-----END PGP SIGNATURE-----


--===============6565860784301590863==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCah8lWQAKCRCb9qggYcy5
ISttAQDwhxjWeHjWw0pBk5k/xOnKOAMfb7K9uU41UxQ+3KVSlgEAhEsVAC+5rVGM
ayA3dGMWkfaQ7O7sgycMssHCxuMmbA0=
=vPSj
-----END PGP SIGNATURE-----

--===============6565860784301590863==--
]