CVE-2025-3155
7.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 4.0
Source: secalert@redhat.com (Secondary)
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Affected (63)
Products: Gnome: Yelp · Debian: Debian Linux · Redhat: Codeready Linux Builder, Codeready Linux Builder For Arm64, Codeready Linux Builder For Arm64 Eus, Codeready Linux Builder For Eus, Codeready Linux Builder For Ibm Z Systems, Codeready Linux Builder For Ibm Z Systems Eus, Codeready Linux Builder For Power Little Endian, Codeready Linux Builder For Power Little Endian Eus, Enterprise Linux, Enterprise Linux Eus, Enterprise Linux For Arm 64, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Update Services For Sap Solutions
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.0_aarch64 | |
| Version 8.8_aarch64 | |
| Version 8.8 | |
| Version 8.0_s390x | |
| Version 8.8_s390x | |
| Version 8.0_ppc64le | |
| Version 8.8_ppc64le | |
| Version 8.0 | |
| Version 9.2 | |
| Version 8.0 | |
| Version 9.4_aarch64 | |
| Version 8.0_s390x | |
| Version 8.8_s390x | |
| Version 8.0_ppc64le | |
| Version 8.8_ppc64le | |
| Version 8.2 | |
| Version 8.4 | |
| Version 8.4 |
References (16)
Source: secalert@redhat.com
ExploitIssue TrackingThird Party Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory
Timeline
No history available yet.