Bug 2008606 (CVE-2021-3828) - CVE-2021-3828 python-nltk: ReDoS vulnerability in Corpus Reader
Summary: CVE-2021-3828 python-nltk: ReDoS vulnerability in Corpus Reader
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2021-3828
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2008607
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-09-28 16:36 UTC by Guilherme de Almeida Suckevicz
Modified: 2021-09-28 18:21 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2021-09-28 18:21:12 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2021-09-28 16:36:36 UTC
nltk is vulnerable to Inefficient Regular Expression Complexity

Reference:
https://huntr.dev/bounties/d19aed43-75bc-4a03-91a0-4d0bb516bc32

Upstream patch:
https://github.com/nltk/nltk/commit/277711ab1dec729e626b27aab6fa35ea5efbd7e6

Comment 1 Guilherme de Almeida Suckevicz 2021-09-28 16:36:52 UTC
Created python-nltk tracking bugs for this issue:

Affects: fedora-all [bug 2008607]

Comment 2 Product Security DevOps Team 2021-09-28 18:21:12 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.