CVE-2014-3577: Apache HttpComponents client: Hostname verification susceptible to MITM attack

2014-08-18 Thread Dirk-Willem van Gulik
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Security Advisory - Apache Software Foundation Apache HttpComponents / hc.apache.org Hostname verification susceptible to MITM attack CVE-2014-3577 / CVSS 1.4 Apache HttpComponents

[ANNOUNCE] Apache POI 3.10.1 released

2014-08-18 Thread Uwe Schindler
The Apache POI project is pleased to announce the release of POI 3.10.1-20140818. This release is a bugfix release to fix two security issues with OOXML. See the downloads page for binary and source distributions: http://poi.apache.org/download.html Note: The Apache Software Foundation uses

[ANNOUNCEMENT] Apache Nutch 1.9 Release

2014-08-18 Thread lewis john mcgibbney
Hi Everyone, The Apache Nutch PMC are pleased to announce the immediate release of Apache Nutch v1.9, we advise all current users and developers of the 1.X series to upgrade to this release. Apache Nutch is a highly extensible and scalable open source web crawler software project. Nutch is a

[ANNOUNCE] [SECURITY] Recommendation to update Apache POI in Apache Solr 4.8.0, 4.8.1, and 4.9.0 installations

2014-08-18 Thread Uwe Schindler
the following files from the base folder of the Apache POI distribution to the solr-4.X.X/contrib/extraction/lib folder: # poi-3.10.1-20140818.jar # poi-ooxml-3.10.1-20140818.jar # poi-ooxml-schemas-3.10.1-20140818.jar # poi-scratchpad-3.10.1-20140818.jar - Copy xmlbeans