diff options
| author | Gyorgy Sarvari <skandigraun@gmail.com> | 2026-03-06 19:33:44 +0100 |
|---|---|---|
| committer | Anuj Mittal <anuj.mittal@oss.qualcomm.com> | 2026-03-09 07:49:30 +0530 |
| commit | a892f6cfc9a5b354966790660118e1277f6f07f2 (patch) | |
| tree | f0cb7d8823ddd141698b5d9a68cb3c0a116b81b2 /meta-python/recipes-devtools/python3-nltk | |
| parent | 7d3016495f194d74b8963d11931daabfb52742f5 (diff) | |
| download | meta-openembedded-a892f6cfc9a5b354966790660118e1277f6f07f2.tar.gz | |
python3-nltk: upgrade 3.9.2 -> 3.9.3
Contains fix for CVE-2026-14009.
Changelog:
* Fix CVE-2025-14009: secure ZIP extraction in nltk.downloader
* Block path traversal/arbitrary reads in nltk.data for protocol-less refs
* Block path traversal/abs paths in corpus readers and FS pointers
* Validate external StanfordSegmenter JARs using SHA256
* Add optional sandbox enforcement for filestring()
* Maintenance: downloader/zipped models, CI/tooling updates
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 14d464c15094d1758dc14706646a8aa645a3bf34)
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Diffstat (limited to 'meta-python/recipes-devtools/python3-nltk')
| -rw-r--r-- | meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.3.bb (renamed from meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.2.bb) | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.2.bb b/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.3.bb index 8a1e0cc047..1748cf6826 100644 --- a/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.2.bb +++ b/meta-python/recipes-devtools/python3-nltk/python3-nltk_3.9.3.bb | |||
| @@ -21,4 +21,4 @@ RRECOMMENDS:${PN} = "\ | |||
| 21 | 21 | ||
| 22 | inherit setuptools3 pypi | 22 | inherit setuptools3 pypi |
| 23 | 23 | ||
| 24 | SRC_URI[sha256sum] = "0f409e9b069ca4177c1903c3e843eef90c7e92992fa4931ae607da6de49e1419" | 24 | SRC_URI[sha256sum] = "cb5945d6424a98d694c2b9a0264519fab4363711065a46aa0ae7a2195b92e71f" |
