← Back

CVE-2025-3155

nvd nist
Published: Apr 3, 2025Modified: Jun 29, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 4.0
Source: secalert@redhat.com (Secondary)

Description

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

Affected (63)

1 product
Yelp
1 product
Debian Linux
19 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.2-8
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration C
61 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 8.0
Version 9.0
Redhat
Version 8.0_aarch64
Version 9.0_aarch64
Redhat
Version 8.8_aarch64
Version 9.2_aarch64
Version 9.4_aarch64
Version 9.6_aarch64
Redhat
Version 8.8
Version 9.2
Version 9.4
Redhat
Version 8.0_s390x
Version 9.0_s390x
Redhat
Version 8.8_s390x
Version 9.2_s390x
Version 9.4_s390x
Version 9.6_s390x
Redhat
Version 8.0_ppc64le
Version 9.0_ppc64le
Redhat
Version 8.8_ppc64le
Version 9.2_ppc64le
Version 9.4_ppc64le
Version 9.6_ppc64le
Redhat
Version 8.0
Version 9.0
Redhat
Version 9.2
Version 9.4
Version 9.6
Redhat
Version 8.0
Version 8.8_aarch64
Version 9.0_aarch64
Version 9.2_aarch64
Redhat
Version 9.4_aarch64
Version 9.6_aarch64
Redhat
Version 8.0_s390x
Version 9.0_s390x
Redhat
Version 8.8_s390x
Version 9.2_s390x
Version 9.4_s390x
Version 9.6_s390x
Redhat
Version 8.0_ppc64le
Version 9.0_ppc64le
Redhat
Version 8.8_ppc64le
Version 9.2_ppc64le
Version 9.4_ppc64le
Version 9.6_ppc64le
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 9.2
Version 9.4
Version 9.6
Redhat
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 8.4
Version 8.6
Version 8.8
Version 9.0
Version 9.2
Version 9.4

References (16)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.