NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
Metrics
Affected Vendors & Products
References
History
Sun, 15 Sep 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-300 | CWE-502 |
Mon, 19 Aug 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-06-27T00:00:00
Updated: 2024-09-15T19:27:36.034Z
Reserved: 2024-06-27T00:00:00
Link: CVE-2024-39705
Vulnrichment
Updated: 2024-08-19T07:47:43.179Z
NVD
Status : Awaiting Analysis
Published: 2024-06-27T22:15:10.543
Modified: 2024-09-15T20:35:02.817
Link: CVE-2024-39705
Redhat
No data.