ALT-BU-2024-16147-1
Branch sisyphus_e2k update bulletin.
Package python3-module-mallard-ducktype updated to version 1.0.2-alt2 for branch sisyphus_e2k.
Closed bugs
migrate from setuptools' test command
Package python3-module-langdetect updated to version 1.0.9-alt2 for branch sisyphus_e2k.
Closed bugs
migrate from setuptools' test command
Package python3-module-arrow updated to version 1.3.0-alt1.1 for branch sisyphus_e2k.
Closed bugs
remove build dependency on python3-module-chai
Package lxqt updated to version 2.1.0-alt2 for branch sisyphus_e2k.
Closed bugs
lxqt 2.0.0 имеет проблему шрифта qt5 приложений
Package python3-module-Cython updated to version 3.0.11-alt1 for branch sisyphus_e2k.
Closed bugs
Cython: обновить до 3.0.10
Package arrow updated to version 12.0.0-alt2.3 for branch sisyphus_e2k.
Closed bugs
arrow: FTBFS
Package python3-module-nltk updated to version 3.9.1-alt2.p11.1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2024-07075
Уязвимость функции nltk.download() пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2024-39705
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
- https://github.com/nltk/nltk/issues/2522
- https://github.com/nltk/nltk/issues/2522
- https://github.com/nltk/nltk/issues/3266
- https://github.com/nltk/nltk/issues/3266
- https://www.vicarius.io/vsociety/posts/rce-in-python-nltk-cve-2024-39705-39706
- https://www.vicarius.io/vsociety/posts/rce-in-python-nltk-cve-2024-39705-39706
Closed bugs
Resource wordnet not found
Package onboard updated to version 1.4.2-alt1 for branch sisyphus_e2k.
Closed bugs
onboard: new version
Package flatpak updated to version 1.14.10-alt1.1 for branch sisyphus_e2k.
Closed bugs
Нужно добавить p11-kit-server, как зависимость