USN-8756-1: Yelp vulnerability
AI summary · glm-5.3
Ubuntu patches Yelp help viewer flaw allowing crafted help documents to execute arbitrary scripts and expose sensitive user information.
USN-8756-1 fixes a vulnerability in Yelp, Ubuntu's help viewer, where help documents could execute arbitrary scripts. An attacker could trick a user into opening a specially crafted help document to obtain sensitive information. Ubuntu has released updated packages.
- Yelp help documents could execute arbitrary scripts when opened
- Attack requires user to open a specially crafted help document
- Impact is sensitive information disclosure via social engineering
Full article
It was discovered that Yelp allowed help documents to execute arbitrary scripts. An attacker could possibly use this issue to trick a user into opening a specially crafted help document and obtain sensitive information.
This source does not provide full text. Read it at ubuntu.com.