CVE-2024-39705
EUVD-2024-011827.06.2024, 22:15
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nltk | nltk | 𝑥 ≤ 3.8.1 | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References