CVE-2021-3828
published 2021-09-27CVE-2021-3828: nltk is vulnerable to Inefficient Regular Expression Complexity
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.65%
73.9th percentile
nltk is vulnerable to Inefficient Regular Expression Complexity
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nltk | < nltk 3.6.5-1 (bookworm) | nltk 3.6.5-1 (bookworm) |
| nltk | nltk | <= 3.6.3 | — |
| nltk | nltk | >= 0 < 3.6.5-1 | 3.6.5-1 |
| nltk | nltk | >= 0 < 3.6.5-1 | 3.6.5-1 |
| nltk | nltk | >= 0 < 3.6.5-1 | 3.6.5-1 |
| nltk | nltk | >= 0 < 3.6.4 | 3.6.4 |
| nltk | nltk_nltk | unspecified – 3.6.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
NLTK Vulnerable to REDoS
osv·2021-09-29
CVE-2021-3828 [HIGH] NLTK Vulnerable to REDoS
NLTK Vulnerable to REDoS
The nltk package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide as an input to the [`_read_comparison_block()`(https://github.com/nltk/nltk/blob/23f4b1c4b4006b0cb3ec278e801029557cec4e82/nltk/corpus/reader/comparative_sents.py#L259) function in the file `nltk/corpus/reader/comparative_sents.py` may cause an application to consume an excessive amount of CPU.
GHSA
NLTK Vulnerable to REDoS
ghsa·2021-09-29
CVE-2021-3828 [HIGH] CWE-1333 NLTK Vulnerable to REDoS
NLTK Vulnerable to REDoS
The nltk package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide as an input to the [`_read_comparison_block()`(https://github.com/nltk/nltk/blob/23f4b1c4b4006b0cb3ec278e801029557cec4e82/nltk/corpus/reader/comparative_sents.py#L259) function in the file `nltk/corpus/reader/comparative_sents.py` may cause an application to consume an excessive amount of CPU.
OSV
CVE-2021-3828: nltk is vulnerable to Inefficient Regular Expression Complexity
osv·2021-09-27·CVSS 7.5
CVE-2021-3828 [HIGH] CVE-2021-3828: nltk is vulnerable to Inefficient Regular Expression Complexity
nltk is vulnerable to Inefficient Regular Expression Complexity
Ubuntu
NLTK vulnerability
vendor_ubuntu·2022-01-10
CVE-2021-3828 NLTK vulnerability
Title: NLTK vulnerability
Summary: NLTK could be made to crash if it received specially crafted
input.
Srikantha Prathi discovered that NLTK incorrectly handled specially crafted input.
An attacker could use this vulnerability to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3828: nltk - nltk is vulnerable to Inefficient Regular Expression Complexity
vendor_debian·2021·CVSS 7.5
CVE-2021-3828 [HIGH] CVE-2021-3828: nltk - nltk is vulnerable to Inefficient Regular Expression Complexity
nltk is vulnerable to Inefficient Regular Expression Complexity
Scope: local
bookworm: resolved (fixed in 3.6.5-1)
bullseye: open
forky: resolved (fixed in 3.6.5-1)
sid: resolved (fixed in 3.6.5-1)
trixie: resolved (fixed in 3.6.5-1)
No detection rules found.
No public exploits indexed.
2021-09-27
Published