USN-7447-1

Source
https://ubuntu.com/security/notices/USN-7447-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7447-1
Related
Published
2025-04-23T12:20:21.243311Z
Modified
2025-04-23T12:20:21.243311Z
Summary
yelp, yelp-xsl vulnerability
Details

It was discovered that Yelp incorrectly handled paths in ghelp URLs. A remote attacker could use this issue to trick users into opening malicious downloaded help files and exfiltrate sensitive information.

References

Affected packages

Ubuntu:20.04:LTS / yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@3.36.2-0ubuntu1.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.2-0ubuntu1.1

Affected versions

3.*

3.34.0-1
3.36.0-1
3.36.2-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.36.2-0ubuntu1.1",
            "binary_name": "libyelp-dev"
        },
        {
            "binary_version": "3.36.2-0ubuntu1.1",
            "binary_name": "libyelp0"
        },
        {
            "binary_version": "3.36.2-0ubuntu1.1",
            "binary_name": "libyelp0-dbgsym"
        },
        {
            "binary_version": "3.36.2-0ubuntu1.1",
            "binary_name": "yelp"
        },
        {
            "binary_version": "3.36.2-0ubuntu1.1",
            "binary_name": "yelp-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@3.36.0-1ubuntu0.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.0-1ubuntu0.1

Affected versions

3.*

3.34.0-1
3.34.2-1
3.36.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.36.0-1ubuntu0.1",
            "binary_name": "yelp-xsl"
        }
    ]
}

Ubuntu:22.04:LTS / yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@42.1-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-1ubuntu0.1

Affected versions

40.*

40.stable-1build1

41.*

41.1-1
41.2-1

Other

42~beta-2

42.*

42.0-1
42.1-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.1-1ubuntu0.1",
            "binary_name": "libyelp-dev"
        },
        {
            "binary_version": "42.1-1ubuntu0.1",
            "binary_name": "libyelp0"
        },
        {
            "binary_version": "42.1-1ubuntu0.1",
            "binary_name": "libyelp0-dbgsym"
        },
        {
            "binary_version": "42.1-1ubuntu0.1",
            "binary_name": "yelp"
        },
        {
            "binary_version": "42.1-1ubuntu0.1",
            "binary_name": "yelp-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@42.0-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.0-1ubuntu0.1

Affected versions

40.*

40.2-2

41.*

41.0-1
41.1-1

Other

42~beta-1

42.*

42.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.0-1ubuntu0.1",
            "binary_name": "yelp-xsl"
        }
    ]
}

Ubuntu:24.10 / yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@42.2-1ubuntu0.24.10.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.2-1ubuntu0.24.10.1

Affected versions

42.*

42.2-1build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.2-1ubuntu0.24.10.1",
            "binary_name": "libyelp-dev"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.10.1",
            "binary_name": "libyelp0"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.10.1",
            "binary_name": "libyelp0-dbgsym"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.10.1",
            "binary_name": "yelp"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.10.1",
            "binary_name": "yelp-dbgsym"
        }
    ]
}

Ubuntu:24.10 / yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@42.1-2ubuntu0.24.10.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-2ubuntu0.24.10.1

Affected versions

42.*

42.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.1-2ubuntu0.24.10.1",
            "binary_name": "yelp-xsl"
        }
    ]
}

Ubuntu:24.04:LTS / yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@42.2-1ubuntu0.24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.2-1ubuntu0.24.04.1

Affected versions

42.*

42.2-1
42.2-1build1
42.2-1build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.2-1ubuntu0.24.04.1",
            "binary_name": "libyelp-dev"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.04.1",
            "binary_name": "libyelp0"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.04.1",
            "binary_name": "libyelp0-dbgsym"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.04.1",
            "binary_name": "yelp"
        },
        {
            "binary_version": "42.2-1ubuntu0.24.04.1",
            "binary_name": "yelp-dbgsym"
        }
    ]
}

Ubuntu:24.04:LTS / yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@42.1-2ubuntu0.24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-2ubuntu0.24.04.1

Affected versions

42.*

42.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.1-2ubuntu0.24.04.1",
            "binary_name": "yelp-xsl"
        }
    ]
}

Ubuntu:25.04 / yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@42.2-2ubuntu0.1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.2-2ubuntu0.1

Affected versions

42.*

42.2-1build2
42.2-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.2-2ubuntu0.1",
            "binary_name": "libyelp-dev"
        },
        {
            "binary_version": "42.2-2ubuntu0.1",
            "binary_name": "libyelp0"
        },
        {
            "binary_version": "42.2-2ubuntu0.1",
            "binary_name": "libyelp0-dbgsym"
        },
        {
            "binary_version": "42.2-2ubuntu0.1",
            "binary_name": "yelp"
        },
        {
            "binary_version": "42.2-2ubuntu0.1",
            "binary_name": "yelp-dbgsym"
        }
    ]
}

Ubuntu:25.04 / yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@42.1-3ubuntu0.1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-3ubuntu0.1

Affected versions

42.*

42.1-2
42.1-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "42.1-3ubuntu0.1",
            "binary_name": "yelp-xsl"
        }
    ]
}