Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper Input Validation in nltk/nltk
Vulnerability Description
In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for `info.url` through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.
CVSS Information
N/A
Vulnerability Type
下载代码缺少完整性检查
Vulnerability Title
NLTK 软件供应链问题漏洞
Vulnerability Description
NLTK是NLTK组织开源的一个自然语言处理工具包。 NLTK 3.9.4版本存在软件供应链问题漏洞,该漏洞源于`nltk.downloader.Downloader._download_package()`函数在强制执行SHA-256或MD5校验和验证前将下载的包字节写入磁盘并可能解压,可能导致攻击者通过受损镜像或恶意代理篡改包响应,安装攻击者控制的包字节,使恶意语料库或模型内容被下游用户或应用信任。
CVSS Information
N/A
Vulnerability Type
N/A