CVE-2019-14751: Path Traversal
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
Other sources
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-14751?
CVE-2019-14751 is a directory traversal vulnerability in NLTK Downloader before version 3.4.5.
How does CVE-2019-14751 work?
CVE-2019-14751 allows attackers to write arbitrary files by using '../' in an NLTK package that is mishandled during extraction.
What is the severity of CVE-2019-14751?
The severity of CVE-2019-14751 is high, with a CVSS score of 7.5.
How can I fix CVE-2019-14751?
To fix CVE-2019-14751, update NLTK Downloader to version 3.4.5 or higher.
Where can I find more information about CVE-2019-14751?
You can find more information about CVE-2019-14751 on the NVD website and the GitHub repository for the vulnerability.