USN-7447-1: Yelp vulnerability
It was discovered that Yelp incorrectly handled paths in ghelp URLs. A remote attacker could use this issue to trick users into opening malicious downloaded help files and exfiltrate sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7447-1?
The severity of USN-7447-1 is considered high due to the risk of a remote attacker tricking users into opening malicious files.
How do I fix USN-7447-1?
To fix USN-7447-1, update the 'yelp' and 'yelp-xsl' packages to their recommended versions listed in the advisory.
What versions of Ubuntu are affected by USN-7447-1?
USN-7447-1 affects Ubuntu 20.04, 22.04, 24.04, and 25.04 for both 'yelp' and 'yelp-xsl' packages.
What vulnerabilities does USN-7447-1 address?
USN-7447-1 addresses a vulnerability where Yelp incorrectly handled paths in ghelp URLs allowing potential arbitrary file access.
How can a remote attacker exploit USN-7447-1?
A remote attacker can exploit USN-7447-1 by deceiving users into opening malicious help files, which could lead to information exfiltration.