Bugzilla – Bug 1191030
VUL-1: CVE-2021-3828: python-nltk: ReDOS vulnerability in Corpus Reader
Last modified: 2022-07-03 19:15:57 UTC
nltk is vulnerable to Inefficient Regular Expression Complexity References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3828 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3828 https://github.com/nltk/nltk/commit/277711ab1dec729e626b27aab6fa35ea5efbd7e6 https://huntr.dev/bounties/d19aed43-75bc-4a03-91a0-4d0bb516bc32
Affected Packages: - openSUSE:Backports:SLE-15-SP2/python-nltk 3.4.5 - openSUSE:Backports:SLE-15-SP3/python-nltk 3.4.5 - openSUSE:Backports:SLE-15-SP4/python-nltk 3.4.5 - openSUSE:Factory/python-nltk 3.5 Upstream patch: https://github.com/nltk/nltk/commit/277711ab1dec729e626b27aab6fa35ea5efbd7e6
This is an autogenerated message for OBS integration: This bug (1191030) was mentioned in https://build.opensuse.org/request/show/965220 Factory / python-nltk
This is an autogenerated message for OBS integration: This bug (1191030) was mentioned in https://build.opensuse.org/request/show/975420 Backports:SLE-15-SP2 / python-nltk https://build.opensuse.org/request/show/975421 Backports:SLE-15-SP4 / python-nltk
This is an autogenerated message for OBS integration: This bug (1191030) was mentioned in https://build.opensuse.org/request/show/985711 Backports:SLE-15-SP2 / python-nltk
openSUSE-SU-2022:10040-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1146427,1191030 CVE References: CVE-2019-14751,CVE-2021-3828 JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): python-nltk-3.7-bp152.3.3.1