Описание
Security update for python-nltk
This update for python-nltk fixes the following issues:
- CVE-2024-39705: Fixed remote code execution through unsafe pickle usage (boo#1227174).
Список пакетов
SUSE Package Hub 15 SP6
python3-nltk-3.7-bp156.4.3.1
openSUSE Leap 15.6
python3-nltk-3.7-bp156.4.3.1
Ссылки
- E-Mail link for openSUSE-SU-2024:0221-1
- SUSE Security Ratings
- SUSE Bug 1227174
- SUSE CVE CVE-2024-39705 page
Описание
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
Затронутые продукты
SUSE Package Hub 15 SP6:python3-nltk-3.7-bp156.4.3.1
openSUSE Leap 15.6:python3-nltk-3.7-bp156.4.3.1
Ссылки
- CVE-2024-39705
- SUSE Bug 1227174