Bug 1146427 - (CVE-2019-14751) VUL-1: CVE-2019-14751: python-nltk: Natural Language Toolkit (NLTK) prior to version 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash)
(CVE-2019-14751)
VUL-1: CVE-2019-14751: python-nltk: Natural Language Toolkit (NLTK) prior to ...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/240518/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-08-20 15:46 UTC by Wolfgang Frisch
Modified: 2022-07-03 19:15 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2019-08-20 15:46:00 UTC
CVE-2019-14751

Natural Language Toolkit (NLTK) prior to version 3.4.5 is vulnerable to a
directory traversal, allowing attackers to write arbitrary files via a ../ (dot
dot slash) in an NLTK package (ZIP archive) that is mishandled during
extraction.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14751
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14751.html
Comment 1 Dirk Mueller 2020-03-24 19:13:16 UTC
This has been already fixed for Leap 15.2 and Tumbleweed. I"ve submitted now an update for Leap 15.1 including the bug reference.
Comment 2 Swamp Workflow Management 2020-03-24 19:50:06 UTC
This is an autogenerated message for OBS integration:
This bug (1146427) was mentioned in
https://build.opensuse.org/request/show/787913 Factory / python-nltk
https://build.opensuse.org/request/show/787914 15.1 / python-nltk
Comment 3 Swamp Workflow Management 2020-03-31 19:13:55 UTC
openSUSE-SU-2020:0436-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1146427
CVE References: CVE-2019-14751
Sources used:
openSUSE Leap 15.1 (src):    python-nltk-3.4.5-lp151.4.3.1
Comment 4 Swamp Workflow Management 2020-04-01 13:29:45 UTC
openSUSE-SU-2020:0440-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1146427
CVE References: CVE-2019-14751
Sources used:
openSUSE Backports SLE-15-SP1 (src):    python-nltk-3.4.5-bp151.4.3.1
Comment 5 Alexandros Toptsoglou 2020-05-04 12:16:15 UTC
Done
Comment 6 OBSbugzilla Bot 2022-06-29 08:40:02 UTC
This is an autogenerated message for OBS integration:
This bug (1146427) was mentioned in
https://build.opensuse.org/request/show/985711 Backports:SLE-15-SP2 / python-nltk
Comment 7 Swamp Workflow Management 2022-07-03 19:15:53 UTC
openSUSE-SU-2022:10040-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1146427,1191030
CVE References: CVE-2019-14751,CVE-2021-3828
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    python-nltk-3.7-bp152.3.3.1