Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39705

Опубликовано: 27 июн. 2024
Источник: debian

Описание

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.9.1-1package
nltkpostponedbookwormpackage
nltkpostponedbullseyepackage

Примечания

  • https://github.com/nltk/nltk/issues/3266

  • https://github.com/nltk/nltk/issues/2522

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

CVSS3: 9.8
nvd
больше 1 года назад

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

suse-cvrf
больше 1 года назад

Security update for python-nltk

suse-cvrf
больше 1 года назад

Security update for python-nltk

CVSS3: 7.5
github
больше 1 года назад

ntlk unsafe deserialization vulnerability