Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-39705
HistoryJun 27, 2024 - 12:00 a.m.

CVE-2024-39705

2024-06-2700:00:00
ubuntu.com
ubuntu.com
1
nltk
remote code execution
pickled python code
untrusted packages
data package download
vulnerability
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

NLTK through 3.8.1 allows remote code execution if untrusted packages have
pickled Python code, and the integrated data package download functionality
is used. This affects, for example, averaged_perceptron_tagger and punkt.

Bugs

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%