QID 981665

QID 981665: Python (pip) Security Update for nltk (GHSA-mr7p-25v2-35wr)

NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-mr7p-25v2-35wr for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981665

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mr7p-25v2-35wr nltk URL Logo github.com/advisories/GHSA-mr7p-25v2-35wr