CVE-2025-3155
yelp - security update
7.4
HIGH
CVSS 3.1
EPSS 12.6%
描述
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
如何修補 CVE-2025-3155
要修補 CVE-2025-3155,請將受影響套件升級到下列已修補版本。
- Debian/yelp—升級至 3.38.3-1+deb11u1 或更新版本
- —升級至 3.38.3-1+deb11u1 或更新版本
- —升級至 42.2-1+deb12u1 或更新版本
- —升級至 3.38.3-1+deb11u1 或更新版本
- —升級至 3.38.3-1+deb11u1 或更新版本
- —升級至 42.1-2+deb12u1 或更新版本
CVE-2025-3155 正在被利用嗎?
中等 — EPSS 為 12.6%,可持續追蹤但非最高優先。
受影響套件(6)
- from 0, < 3.38.3-1+deb11u1
- from 0, < 3.38.3-1+deb11u1
- from 0, < 42.2-1+deb12u1
- from 0, < 3.38.3-1+deb11u1
- from 0, < 3.38.3-1+deb11u1
- from 0, < 42.1-2+deb12u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |