漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unauthenticated Denial of Service in nltk.app.wordnet_app
Vulnerability Description
A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._exit(0)`. This results in a denial of service, impacting service availability. The issue arises due to insufficient authentication and protection mechanisms for critical server functions.
CVSS Information
N/A
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
nltk nltk/nltk 授权问题漏洞
Vulnerability Description
NLTK是NLTK组织开源的一个自然语言工具包。 用于支持自然语言处理的研究和开发。 nltk nltk/nltk 3.9.3及之前版本存在授权问题漏洞,该漏洞源于对关键服务器功能的身份验证和保护机制不足,可能导致未经身份验证的远程攻击者通过发送特定的未授权GET请求关闭本地WordNet Browser HTTP服务器,造成服务拒绝。
CVSS Information
N/A
Vulnerability Type
N/A