USN-7447-1

Source
https://ubuntu.com/security/notices/USN-7447-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7447-1
Upstream
Related
Published
2025-04-23T12:20:21Z
Modified
2026-02-10T04:48:31Z
Summary
yelp, yelp-xsl vulnerability
Details

It was discovered that Yelp incorrectly handled paths in ghelp URLs. A remote attacker could use this issue to trick users into opening malicious downloaded help files and exfiltrate sensitive information.

References

Affected packages

Ubuntu:20.04:LTS
yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@3.36.2-0ubuntu1.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.2-0ubuntu1.1

Affected versions

3.*
3.34.0-1
3.36.0-1
3.36.2-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libyelp-dev",
            "binary_version": "3.36.2-0ubuntu1.1"
        },
        {
            "binary_name": "libyelp0",
            "binary_version": "3.36.2-0ubuntu1.1"
        },
        {
            "binary_name": "yelp",
            "binary_version": "3.36.2-0ubuntu1.1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-3155",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json"
yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@3.36.0-1ubuntu0.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.0-1ubuntu0.1

Affected versions

3.*
3.34.0-1
3.34.2-1
3.36.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "yelp-xsl",
            "binary_version": "3.36.0-1ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-3155",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json"
Ubuntu:22.04:LTS
yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@42.1-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-1ubuntu0.1

Affected versions

40.*
40.stable-1build1
41.*
41.1-1
41.2-1
Other
42~beta-2
42.*
42.0-1
42.1-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libyelp-dev",
            "binary_version": "42.1-1ubuntu0.1"
        },
        {
            "binary_name": "libyelp0",
            "binary_version": "42.1-1ubuntu0.1"
        },
        {
            "binary_name": "yelp",
            "binary_version": "42.1-1ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-3155",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json"
yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@42.0-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.0-1ubuntu0.1

Affected versions

40.*
40.2-2
41.*
41.0-1
41.1-1
Other
42~beta-1
42.*
42.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "yelp-xsl",
            "binary_version": "42.0-1ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-3155",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json"
Ubuntu:24.04:LTS
yelp

Package

Name
yelp
Purl
pkg:deb/ubuntu/yelp@42.2-1ubuntu0.24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.2-1ubuntu0.24.04.1

Affected versions

42.*
42.2-1
42.2-1build1
42.2-1build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libyelp-dev",
            "binary_version": "42.2-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "libyelp0",
            "binary_version": "42.2-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "yelp",
            "binary_version": "42.2-1ubuntu0.24.04.1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:24.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-3155",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json"
yelp-xsl

Package

Name
yelp-xsl
Purl
pkg:deb/ubuntu/yelp-xsl@42.1-2ubuntu0.24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
42.1-2ubuntu0.24.04.1

Affected versions

42.*
42.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "yelp-xsl",
            "binary_version": "42.1-2ubuntu0.24.04.1"
        }
    ]
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:24.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-3155",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7447-1.json"