Bug 1191030 - (CVE-2021-3828) VUL-1: CVE-2021-3828: python-nltk: ReDOS vulnerability in Corpus Reader
(CVE-2021-3828)
VUL-1: CVE-2021-3828: python-nltk: ReDOS vulnerability in Corpus Reader
Status: IN_PROGRESS
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.3
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/311001/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-09-28 13:17 UTC by Gabriele Sonnu
Modified: 2022-07-03 19:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Gabriele Sonnu 2021-09-28 13:18:06 UTC
Affected Packages:

 - openSUSE:Backports:SLE-15-SP2/python-nltk  3.4.5
 - openSUSE:Backports:SLE-15-SP3/python-nltk  3.4.5
 - openSUSE:Backports:SLE-15-SP4/python-nltk  3.4.5
 - openSUSE:Factory/python-nltk               3.5

Upstream patch:
https://github.com/nltk/nltk/commit/277711ab1dec729e626b27aab6fa35ea5efbd7e6
Comment 2 OBSbugzilla Bot 2022-03-27 19:10:03 UTC
This is an autogenerated message for OBS integration:
This bug (1191030) was mentioned in
https://build.opensuse.org/request/show/965220 Factory / python-nltk
Comment 3 OBSbugzilla Bot 2022-05-06 14:40:03 UTC
This is an autogenerated message for OBS integration:
This bug (1191030) was mentioned in
https://build.opensuse.org/request/show/975420 Backports:SLE-15-SP2 / python-nltk
https://build.opensuse.org/request/show/975421 Backports:SLE-15-SP4 / python-nltk
Comment 4 OBSbugzilla Bot 2022-06-29 08:40:04 UTC
This is an autogenerated message for OBS integration:
This bug (1191030) was mentioned in
https://build.opensuse.org/request/show/985711 Backports:SLE-15-SP2 / python-nltk
Comment 5 Swamp Workflow Management 2022-07-03 19:15:57 UTC
openSUSE-SU-2022:10040-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1146427,1191030
CVE References: CVE-2019-14751,CVE-2021-3828
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    python-nltk-3.7-bp152.3.3.1