ALT-PU-2024-16034-2
Package python3-module-nltk updated to version 3.9.1-alt2.p11.1 for branch p10 in task 363058.
Closed vulnerabilities
Published: 2024-05-19
BDU:2024-07075
Уязвимость функции nltk.download() пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю выполнить произвольный код
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2024-06-28
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2024-39705
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
References:
- https://github.com/nltk/nltk/issues/2522
- https://github.com/nltk/nltk/issues/2522
- https://github.com/nltk/nltk/issues/3266
- https://github.com/nltk/nltk/issues/3266
- https://www.vicarius.io/vsociety/posts/rce-in-python-nltk-cve-2024-39705-39706
- https://www.vicarius.io/vsociety/posts/rce-in-python-nltk-cve-2024-39705-39706
Closed bugs
Resource wordnet not found