{"id":"openSUSE-SU-2022:10040-1","summary":"Security update for python-nltk","details":"This update for python-nltk fixes the following issues:\n\nUpdate to 3.7\n\n  - Improve and update the NLTK team page on nltk.org (#2855,\n    #2941)\n  - Drop support for Python 3.6, support Python 3.10 (#2920)\n\n- Update to 3.6.7\n\n  - Resolve IndexError in `sent_tokenize` and `word_tokenize`\n    (#2922)\n\n- Update to 3.6.6\n\n  - Refactor `gensim.doctest` to work for gensim 4.0.0 and up\n    (#2914)\n  - Add Precision, Recall, F-measure, Confusion Matrix to Taggers\n    (#2862)\n  - Added warnings if .zip files exist without any corresponding\n    .csv files. (#2908)\n  - Fix `FileNotFoundError` when the `download_dir` is\n    a non-existing nested folder (#2910)\n  - Rename omw to omw-1.4 (#2907)\n  - Resolve ReDoS opportunity by fixing incorrectly specified\n    regex (#2906, boo#1191030, CVE-2021-3828).\n  - Support OMW 1.4 (#2899)\n  - Deprecate Tree get and set node methods (#2900)\n  - Fix broken inaugural test case (#2903)\n  - Use Multilingual Wordnet Data from OMW with newer Wordnet\n    versions (#2889)\n  - Keep NLTKs 'tokenize' module working with pathlib (#2896)\n  - Make prettyprinter to be more readable (#2893)\n  - Update links to the nltk book (#2895)\n  - Add `CITATION.cff` to nltk (#2880)\n  - Resolve serious ReDoS in PunktSentenceTokenizer (#2869)\n  - Delete old CI config files (#2881)\n  - Improve Tokenize documentation + add TokenizerI as superclass\n    for TweetTokenizer (#2878)\n  - Fix expected value for BLEU score doctest after changes from\n    #2572\n  - Add multi Bleu functionality and tests (#2793)\n  - Deprecate 'return_str' parameter in NLTKWordTokenizer and\n    TreebankWordTokenizer (#2883)\n  - Allow empty string in CFG's + more (#2888)\n  - Partition `tree.py` module into `tree` package + pickle fix\n    (#2863)\n  - Fix several TreebankWordTokenizer and NLTKWordTokenizer bugs\n    (#2877)\n  - Rewind Wordnet data file after each lookup (#2868)\n  - Correct __init__ call for SyntaxCorpusReader subclasses\n    (#2872)\n  - Documentation fixes (#2873)\n  - Fix levenstein distance for duplicated letters (#2849)\n  - Support alternative Wordnet versions (#2860)\n  - Remove hundreds of formatting warnings for nltk.org (#2859)\n  - Modernize `nltk.org/howto` pages (#2856)\n  - Fix Bleu Score smoothing function from taking log(0) (#2839)\n  - Update third party tools to newer versions and removing\n    MaltParser fixed version (#2832)\n  - Fix TypeError: _pretty() takes 1 positional argument but 2\n    were given in sem/drt.py (#2854)\n  - Replace `http` with `https` in most URLs (#2852)\n\n- Update to 3.6.5\n\n  - modernised nltk.org website\n  - addressed LGTM.com issues\n  - support ZWJ sequences emoji and skin tone modifer emoji in\n    TweetTokenizer\n  - METEOR evaluation now requires pre-tokenized input\n  - Code linting and type hinting\n  - implement get_refs function for DrtLambdaExpression\n  - Enable automated CoreNLP, Senna, Prover9/Mace4, Megam,\n    MaltParser CI tests\n  - specify minimum regex version that supports regex.Pattern\n  - avoid re.Pattern and regex.Pattern which fail for Python 3.6,\n    3.7\n\n- Update to 3.6.4\n\n  - deprecate `nltk.usage(obj)` in favor of `help(obj)`\n  - resolve ReDoS vulnerability in Corpus Reader\n  - solidify performance tests\n  - improve phone number recognition in tweet tokenizer\n  - refactored CISTEM stemmer for German\n  - identify NLTK Team as the author\n  - replace travis badge with github actions badge\n  - add SECURITY.md\n\n- Update to 3.6.3\n\n  - Dropped support for Python 3.5\n  - Run CI tests on Windows, too\n  - Moved from Travis CI to GitHub Actions\n  - Code and comment cleanups\n  - Visualize WordNet relation graphs using Graphviz\n  - Fixed large error in METEOR score\n  - Apply isort, pyupgrade, black, added as pre-commit hooks\n  - Prevent debug_decisions in Punkt from throwing IndexError\n  - Resolved ZeroDivisionError in RIBES with dissimilar sentences\n  - Initialize WordNet IC total counts with smoothing value\n  - Fixed AttributeError for Arabic ARLSTem2 stemmer\n  - Many fixes and improvements to lm language model package\n  - Fix bug in nltk.metrics.aline, C_skip = -10\n  - Improvements to TweetTokenizer\n  - Optional show arg for FreqDist.plot, ConditionalFreqDist.plot\n  - edit_distance now computes Damerau-Levenshtein edit-distance\n\n- Update to 3.6.2\n\n  - move test code to nltk/test\n  - fix bug in NgramAssocMeasures (order preserving fix)\n\n- Update to 3.6\n\n  - add support for Python 3.9\n  - add Tree.fromlist\n  - compute Minimum Spanning Tree of unweighted graph using BFS\n  - fix bug with infinite loop in Wordnet closure and tree\n  - fix bug in calculating BLEU using smoothing method 4\n  - Wordnet synset similarities work for all pos\n  - new Arabic light stemmer (ARLSTem2)\n  - new syllable tokenizer (LegalitySyllableTokenizer)\n  - remove nose in favor of pytest\n\n- Update to v3.5\n\n  * add support for Python 3.8\n  * drop support for Python 2\n  * create NLTK's own Tokenizer class distinct from the Treebank\n    reference tokeniser\n  * update Vader sentiment analyser\n  * fix JSON serialization of some PoS taggers\n  * minor improvements in grammar.CFG, Vader, pl196x corpus reader,\n    StringTokenizer\n  * change implementation \u003c= and \u003e= for FreqDist so they are partial\n    orders\n  * make FreqDist iterable\n  * correctly handle Penn Treebank trees with a unlabeled branching\n    top node\n\n- Update to 3.4.5 (boo#1146427, CVE-2019-14751):","modified":"2026-03-11T07:33:27.659370Z","published":"2022-07-03T14:01:14Z","related":["CVE-2019-14751","CVE-2021-3828"],"upstream":["CVE-2019-14751","CVE-2021-3828"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/6ZUSFUYB3S2F4VLUQBWFBYRLCIHMR43P/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146427"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14751"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3828"}],"affected":[{"package":{"name":"python-nltk","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/python-nltk&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.7-bp152.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"python3-nltk":"3.7-bp152.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10040-1.json"}}],"schema_version":"1.7.5"}