openSUSE-SU-2020:0440-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0440-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2020:0440-1
Related
Published
2020-04-01T07:47:41Z
Modified
2020-04-01T07:47:41Z
Summary
Security update for python-nltk
Details

This update for python-nltk fixes the following issues:

Update to 3.4.5 (boo#1146427, CVE-2019-14751):

  • CVE-2019-14751: Fixed Zip slip vulnerability in downloader for the unlikely situation where a user configures their downloader to use a compromised server (boo#1146427)

Update to 3.4.4:

  • fix bug in plot function (probability.py)
  • add improved PanLex Swadesh corpus reader
  • add Text.generate()
  • add QuadgramAssocMeasures
  • add SSP to tokenizers
  • return confidence of best tag from AveragedPerceptron
  • make plot methods return Axes objects
  • don't require list arguments to PositiveNaiveBayesClassifier.train
  • fix Tree classes to work with native Python copy library
  • fix inconsistency for NomBank
  • fix random seeding in LanguageModel.generate
  • fix ConditionalFreqDist mutation on tabulate/plot call
  • fix broken links in documentation
  • fix misc Wordnet issues
  • update installation instructions

Version update to 3.4.1:

  • add chomskynormalform for CFGs
  • add meteor score
  • add minimum edit/Levenshtein distance based alignment function
  • allow access to collocation list via text.collocation_list()
  • support corenlp server options
  • drop support for Python 3.4
  • other minor fixes

Update to v3.4:

  • Support Python 3.7
  • New Language Modeling package
  • Cistem Stemmer for German
  • Support Russian National Corpus incl POS tag model
  • Krippendorf Alpha inter-rater reliability test
  • Comprehensive code clean-ups
  • Switch continuous integration from Jenkins to Travis

Updated to v3.3:

  • Support Python 3.6
  • New interface to CoreNLP
  • Support synset retrieval by sense key
  • Minor fixes to CoNLL Corpus Reader
  • AlignedSent
  • Fixed minor inconsistencies in APIs and API documentation
  • Better conformance to PEP8
  • Drop Moses Tokenizer (incompatible license)

This update was imported from the openSUSE:Leap:15.1:Update update project.

References

Affected packages

SUSE:Package Hub 15 SP1 / python-nltk

Package

Name
python-nltk
Purl
pkg:rpm/suse/python-nltk&distro=SUSE%20Package%20Hub%2015%20SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.5-bp151.4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "python3-nltk": "3.4.5-bp151.4.3.1",
            "python2-nltk": "3.4.5-bp151.4.3.1"
        }
    ]
}