[Git][security-tracker-team/security-tracker][master] nltk no-dsa
Moritz Muehlenhoff
jmm at debian.org
Sat Aug 24 13:46:54 BST 2019
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fbe1adf4 by Moritz Muehlenhoff at 2019-08-24T12:46:30Z
nltk no-dsa
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,7 +3,7 @@ CVE-2019-15537 (The proxystatistics module before 3.1.0 for SimpleSAMLphp allows
CVE-2019-15536 (The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injec ...)
NOT-FOR-US: Acclaim block plugin for Moodle
CVE-2019-15535 (Tasking Manager before 3.4.0 allows SQL Injection via custom SQL. ...)
- TODO: check
+ NOT-FOR-US: Tasking Manager
CVE-2019-15534
RESERVED
CVE-2019-15533
@@ -2282,7 +2282,9 @@ CVE-2019-14753
CVE-2019-14752
RESERVED
CVE-2019-14751 (NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, a ...)
- - nltk <unfixed> (bug #935201)
+ - nltk <unfixed> (low; bug #935201)
+ [buster] - nltk <no-dsa> (Minor issue)
+ [stretch] - nltk <no-dsa> (Minor issue)
[jessie] - nltk <no-dsa> (Minor issue; user has to configure a compromised server)
NOTE: https://salvatoresecurity.com/zip-slip-in-nltk-cve-2019-14751/
NOTE: https://github.com/nltk/nltk/commit/f59d7ed8df2e0e957f7f247fe218032abdbe9a10
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/fbe1adf4e041ede5eb00f54483fd5d6c4426549c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/fbe1adf4e041ede5eb00f54483fd5d6c4426549c
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190824/da211d3d/attachment.html>
More information about the debian-security-tracker-commits
mailing list