NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
CVSS

No CVSS.

History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-27T00:00:00

Updated: 2024-06-28T15:01:53.169Z

Reserved: 2024-06-27T00:00:00


Link: CVE-2024-39705

JSON object: View

cve-icon NVD Information

Status : Received

Published: 2024-06-27T22:15:10.543

Modified: 2024-06-27T22:15:10.543


Link: CVE-2024-39705

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.