• Accepted yelp 42.2-3 (source) into unstable

    From Debian FTP Masters@21:1/5 to All on Wed Apr 23 18:40:01 2025
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Format: 1.8
    Date: Wed, 23 Apr 2025 12:17:23 -0400
    Source: yelp
    Built-For-Profiles: noudeb
    Architecture: source
    Version: 42.2-3
    Distribution: unstable
    Urgency: high
    Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
    Changed-By: Jeremy BĂ­cha <jbicha@ubuntu.com>
    Closes: 1102080
    Changes:
    yelp (42.2-3) unstable; urgency=high
    .
    [ Marc Deslauriers ]
    * SECURITY UPDATE: arbitrary script execution
    - debian/patches/CVE-2025-3155.patch: use a nonce in
    data/xslt/mal2html.xsl.in, data/xslt/man2html.xsl.in,
    data/xslt/yelp-common.xsl.in, libyelp/yelp-transform.c,
    libyelp/yelp-view.c.
    - CVE-2025-3155 (Closes: #1102080)
    Checksums-Sha1:
    cc26a8ebda797382dab2c9ebf4ced3dced8002bf 2449 yelp_42.2-3.dsc
    6658e4c049d1dc055adb25131007e83ac092d342 18420 yelp_42.2-3.debian.tar.xz
    85f767f6f68bdaf83be5297bd2c9b817de8b571b 17927 yelp_42.2-3_source.buildinfo Checksums-Sha256:
    895470600351a54f5fa746cdb75529570cf35eda1f85ab5dfc6450c79ff58885 2449 yelp_42.2-3.dsc
    03835e6622ef2585939902e7604c5f7d28cb36530f653db680a71cb368890f92 18420 yelp_42.2-3.debian.tar.xz
    25f3ded83ccd83667f948689a368b0372177cdb92ff9a82fb12a4c5b36f1424b 17927 yelp_42.2-3_source.buildinfo
    Files:
    84498b92ca54cc15a2f8030e0039c09d 2449 gnome optional yelp_42.2-3.dsc
    3b6160c46ac2a837ed008c1f49ac6669 18420 gnome optional yelp_42.2-3.debian.tar.xz
    5cbc67728ba34bd659b1f47bc3327370 17927 gnome optional yelp_42.2-3_source.buildinfo

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmgJEsUACgkQ5mx3Wuv+ bH3RMQ/+KWA+I8LZDNJLogfDOTIPon4LejcCON5/CpnClx8kjhFrluCiJXzKShO2 Tsd57TlXHBOYhR28x8EKi/jhCoHWFsO2tuCeTOsHBhnZ1s6jDY/8MEu96bC0U8t1 XXqS468J+/0o5g/av7+mrVN9j4lCQWRTQokk7fVtvBXsgEtn83UotbFhMMQxASgG wH2oVFxrhruwPdkRn+Ih4HWEiYape2YjB6VtnF/WfPjTkcLnyzd9pAaCBNKMrbVs JazQAguR2vFlwDFlyfP4nS1eADGYW0RLxpDb2UG8xTFt0UmU/j6/uhf5q+wKxeT7 y3mH+5MU1m+jbi2MLJGVXODIr1yxxi9uKVQRVJ4QrYzPPtmyPhLfINOVDhLY5Xez omN9aNIxj9B8dT32S4/K/Z0qvok9Un9B6KzGfa+aExK5i2rIdj8y8IgMIvlj2tuy gYhn5VKbJ6uEZtdf8mKOyC3S5QspuazWu/EGQ0HJajU/8NLdkCMZXzfuzcapK297 X9hPRoWujiqYwvUhfvwGGM1RRlsebfxPF6/ATrARkJSuQodtk/6X4+3VsCSpj10a lmauc3+LoSRrUWVklOu5deixQSiDDgaC5AxN1g0EcUDz2Ky41S30KGhyOf7hjUi1 59RFfQyqka/EZohYCMTaBFPOg2uylwFPGO0qarRQRXhKW5pIxHU=
    =DGk2
    -----END PGP SIGNATURE-----


    --==============!75435939003844489=Content-Type: application/pgp-signature

    -----BEGIN PGP SIGNATURE-----

    iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaAkXHQAKCRCb9qggYcy5 IQqhAP44Pb0F6aBZQZlWmBg9j/sFqBITS0RgSAPato/lVqYtVQEA/7QkQcX8k9pG NgjfIi84EU8nBguX9dv2l2Aj0H855AA=nSm/
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)