Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2019-14751 - CERT CVE
CVE-2019-14751
ID
CVE-2019-14751
Sažetak
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
Reference
https://github.com/nltk/nltk/commit/f59d7ed8df2e0e957f7f247fe218032abdbe9a10
https://salvatoresecurity.com/zip-slip-in-nltk-cve-2019-14751/
https://github.com/nltk/nltk/blob/3.4.5/ChangeLog
https://github.com/mssalvatore/CVE-2019-14751_PoC
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00054.html
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00001.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGZSSEJH7RHH3RBUEVWWYT75QU67J7SE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI4IJGLZQ5S7C5LNRNROHAO2P526XE3D/
CVSS
Base:
5.0
Impact:
2.9
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
NONE
PARTIAL
NONE
CVSS vektor
AV:N/AC:L/Au:N/C:N/I:P/A:N
Zadnje važnije ažuriranje
07-11-2023 - 03:05
Objavljeno
22-08-2019 - 16:15