openSUSE Security Update : python-nltk (openSUSE-2020-436)

high Nessus Plugin ID 135162

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for python-nltk fixes the following issues :

Update to 3.4.5 (boo#1146427, CVE-2019-14751) :

- CVE-2019-14751: Fixed Zip slip vulnerability in downloader for the unlikely situation where a user configures their downloader to use a compromised server (boo#1146427)

Update to 3.4.4 :

- fix bug in plot function (probability.py)

- add improved PanLex Swadesh corpus reader

- add Text.generate()

- add QuadgramAssocMeasures

- add SSP to tokenizers

- return confidence of best tag from AveragedPerceptron

- make plot methods return Axes objects

- don't require list arguments to PositiveNaiveBayesClassifier.train

- fix Tree classes to work with native Python copy library

- fix inconsistency for NomBank

- fix random seeding in LanguageModel.generate

- fix ConditionalFreqDist mutation on tabulate/plot call

- fix broken links in documentation

- fix misc Wordnet issues

- update installation instructions

Version update to 3.4.1 :

- add chomsky_normal_form for CFGs

- add meteor score

- add minimum edit/Levenshtein distance based alignment function

- allow access to collocation list via text.collocation_list()

- support corenlp server options

- drop support for Python 3.4

- other minor fixes

Update to v3.4 :

- Support Python 3.7

- New Language Modeling package

- Cistem Stemmer for German

- Support Russian National Corpus incl POS tag model

- Krippendorf Alpha inter-rater reliability test

- Comprehensive code clean-ups

- Switch continuous integration from Jenkins to Travis

Updated to v3.3 :

- Support Python 3.6

- New interface to CoreNLP

- Support synset retrieval by sense key

- Minor fixes to CoNLL Corpus Reader

- AlignedSent

- Fixed minor inconsistencies in APIs and API documentation

- Better conformance to PEP8

- Drop Moses Tokenizer (incompatible license)

Solution

Update the affected python-nltk packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1146427

Plugin Details

Severity: High

ID: 135162

File Name: openSUSE-2020-436.nasl

Version: 1.3

Type: local

Agent: unix

Published: 4/2/2020

Updated: 3/19/2024

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2019-14751

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:python2-nltk, p-cpe:/a:novell:opensuse:python3-nltk, cpe:/o:novell:opensuse:15.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/31/2020

Vulnerability Publication Date: 8/22/2019

Reference Information

CVE: CVE-2019-14751