Опубликовано: 29 сент. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5
Описание
NLTK Vulnerable to REDoS
The nltk package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide as an input to the [_read_comparison_block()(https://github.com/nltk/nltk/blob/23f4b1c4b4006b0cb3ec278e801029557cec4e82/nltk/corpus/reader/comparative_sents.py#L259) function in the file nltk/corpus/reader/comparative_sents.py may cause an application to consume an excessive amount of CPU.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-3828
- https://github.com/nltk/nltk/pull/2816
- https://github.com/nltk/nltk/commit/277711ab1dec729e626b27aab6fa35ea5efbd7e6
- https://github.com/advisories/GHSA-2ww3-fxvq-293j
- https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2021-356.yaml
- https://huntr.dev/bounties/d19aed43-75bc-4a03-91a0-4d0bb516bc32
Пакеты
Наименование
nltk
pip
Затронутые версииВерсия исправления
< 3.6.4
3.6.4
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 4 лет назад
nltk is vulnerable to Inefficient Regular Expression Complexity
CVSS3: 7.5
nvd
больше 4 лет назад
nltk is vulnerable to Inefficient Regular Expression Complexity
CVSS3: 7.5
debian
больше 4 лет назад
nltk is vulnerable to Inefficient Regular Expression Complexity