1 |
type: security |
2 |
subject: Updated python-nltk packages fix security vulnerability |
3 |
CVE: |
4 |
- CVE-2019-14751 |
5 |
src: |
6 |
7: |
7 |
core: |
8 |
- python-nltk-3.4.5-1.1.mga7 |
9 |
description: | |
10 |
Updated python-ntlk package fixes security vulnerability: |
11 |
|
12 |
A vulnerability was found in NLTK Downloader before 3.4.5 is vulnerable |
13 |
to a directory traversal, allowing attackers to write arbitrary files via |
14 |
a ../ in an NLTK package (ZIP archive) that is mishandled during extraction |
15 |
(CVE-2019-14751). |
16 |
references: |
17 |
- https://bugs.mageia.org/show_bug.cgi?id=26403 |
18 |
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ZGZSSEJH7RHH3RBUEVWWYT75QU67J7SE/ |
19 |
ID: MGASA-2020-0160 |