ANNOUNCE: Apache SpamAssassin 3.4.5 available

2021-03-24 Thread Sidney Markowitz
On behalf of the Apache SpamAssassin Project, I am pleased to announce version 3.4.5 is available. Release Notes -- Apache SpamAssassin -- Version 3.4.5 Introduction Apache SpamAssassin 3.4.5 is primarily a security release. In this release, there are bug fixes for one CVE. ***

[CVE-2020-1946] Apache SpamAssassin malicious rule configuration (.cf) files can be configured to run system commands

2021-03-24 Thread Sidney Markowitz
Apache SpamAssassin 3.4.5 was recently released [1], and fixes an issue of security note where malicious rule configuration (.cf) files can be configured to run system commands. In Apache SpamAssassin before 3.4.5, exploits can be injected in a number of scenarios. In addition to upgrading to

[ANNOUNCE] Apache Qpid JMS 0.57.0 released

2021-03-24 Thread Robbie Gemmell
The Apache Qpid (http://qpid.apache.org) community is pleased to announce the immediate availability of Apache Qpid JMS 0.57.0. This is the latest release of our newer JMS client supporting the Advanced Message Queuing Protocol 1.0 (AMQP 1.0, ISO/IEC 19464, http://www.amqp.org), based around the

The Apache® Software Foundation Celebrates 22 Years of Open Source Innovation "The Apache Way"

2021-03-24 Thread Sally Khudairi
[this announcement is available online at https://s.apache.org/22ndAnniversay ] World's largest Open Source foundation provides $22B+ in community-led software 100% free of charge for the common good Wilmington, DE —24 March 2021— The Apache Software Foundation (ASF), the all-volunteer