OESA-2025-1543

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1543
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-1543.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-1543
Upstream
Published
2025-05-23T14:00:10Z
Modified
2025-09-03T06:31:27.675042Z
Summary
yelp-xsl security update
Details

This package contains XSL stylesheets that are used by the yelp help browser.

Security Fix(es):

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.(CVE-2025-3155)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4

yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:rpm/openEuler/yelp-xsl&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.0-2.oe2003sp4

Ecosystem specific

{
    "src": [
        "yelp-xsl-3.36.0-2.oe2003sp4.src.rpm"
    ],
    "noarch": [
        "yelp-xsl-3.36.0-2.oe2003sp4.noarch.rpm",
        "yelp-xsl-devel-3.36.0-2.oe2003sp4.noarch.rpm",
        "yelp-xsl-help-3.36.0-2.oe2003sp4.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP3

yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:rpm/openEuler/yelp-xsl&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.38.3-2.oe2203sp3

Ecosystem specific

{
    "src": [
        "yelp-xsl-3.38.3-2.oe2203sp3.src.rpm"
    ],
    "noarch": [
        "yelp-xsl-3.38.3-2.oe2203sp3.noarch.rpm",
        "yelp-xsl-devel-3.38.3-2.oe2203sp3.noarch.rpm",
        "yelp-xsl-help-3.38.3-2.oe2203sp3.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP4

yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:rpm/openEuler/yelp-xsl&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.38.3-2.oe2203sp4

Ecosystem specific

{
    "src": [
        "yelp-xsl-3.38.3-2.oe2203sp4.src.rpm"
    ],
    "noarch": [
        "yelp-xsl-3.38.3-2.oe2203sp4.noarch.rpm",
        "yelp-xsl-devel-3.38.3-2.oe2203sp4.noarch.rpm",
        "yelp-xsl-help-3.38.3-2.oe2203sp4.noarch.rpm"
    ]
}

openEuler:24.03-LTS

yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:rpm/openEuler/yelp-xsl&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-2.oe2403sp1

Ecosystem specific

{
    "src": [
        "yelp-xsl-42.1-2.oe2403.src.rpm",
        "yelp-xsl-42.1-2.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "yelp-xsl-42.1-2.oe2403.noarch.rpm",
        "yelp-xsl-devel-42.1-2.oe2403.noarch.rpm",
        "yelp-xsl-42.1-2.oe2403sp1.noarch.rpm",
        "yelp-xsl-devel-42.1-2.oe2403sp1.noarch.rpm"
    ]
}

openEuler:24.03-LTS-SP1

yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:rpm/openEuler/yelp-xsl&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-2.oe2403sp1

Ecosystem specific

{
    "src": [
        "yelp-xsl-42.1-2.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "yelp-xsl-42.1-2.oe2403sp1.noarch.rpm",
        "yelp-xsl-devel-42.1-2.oe2403sp1.noarch.rpm"
    ]
}