NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
Metrics
Affected Vendors & Products
References
History
Sun, 15 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-300 | CWE-502 |
Mon, 19 Aug 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-06-27T00:00:00
Updated: 2024-09-15T19:27:36.034Z
Reserved: 2024-06-27T00:00:00
Link: CVE-2024-39705
Updated: 2024-08-19T07:47:43.179Z
Status : Awaiting Analysis
Published: 2024-06-27T22:15:10.543
Modified: 2024-11-21T09:28:15.537
Link: CVE-2024-39705
No data.