Return-Path: X-Original-To: apmail-announce-archive@www.apache.org Delivered-To: apmail-announce-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 096D918512 for ; Mon, 16 Nov 2015 01:01:35 +0000 (UTC) Received: (qmail 69310 invoked by uid 500); 16 Nov 2015 01:01:19 -0000 Delivered-To: apmail-announce-archive@apache.org Received: (qmail 68808 invoked by uid 500); 16 Nov 2015 01:01:18 -0000 Mailing-List: contact announce-help@apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list announce@apache.org Delivered-To: moderator for announce@apache.org Received: (qmail 63635 invoked by uid 99); 15 Nov 2015 22:24:31 -0000 From: Thomas Neidhart Subject: [ANNOUNCEMENT] Apache Commons Collections 3.2.2 Released Reply-To: Commons Developers List To: announce@apache.org Message-ID: <5649061A.1050703@apache.org> Date: Sun, 15 Nov 2015 23:24:26 +0100 User-Agent: Mozilla/5.0 (X11; Linux i686; rv:38.0) Gecko/20100101 Thunderbird/38.2.0 MIME-Version: 1.0 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit The Apache Commons team is pleased to announce the release of Apache Commons Collections 3.2.2. The release is available for download at http://commons.apache.org/proper/commons-collections/download_collections.cgi Apache Commons Collections is a project to develop and maintain collection classes based on and inspired by the JDK collection framework. This Collections 3.2.2 release is a security and bugfix release, fixing several bugs present in the previous releases of the 3.2 branch. Additionally, this release provides a mitigation for a known remote code exploitation via the standard java object serialization mechanism. By default, serialization support for unsafe classes in the functor package is disabled and will result in an exception when either trying to serialize or de-serialize an instance of these classes. For more details, please refer to COLLECTIONS-580. All users are strongly encouraged to updated to this release. See the release-notes at http://commons.apache.org/proper/commons-collections/release_3_2_2.html http://www.apache.org/dist/commons/collections/RELEASE-NOTES-3.2.2.txt for a full list of changes. Please verify signatures using the KEYS file available at the above location when downloading the release. For complete information on collections, including instructions on how to submit bug reports, patches, or suggestions for improvement, see the Apache Commons Collections website: http://commons.apache.org/proper/commons-collections/ Thomas, on behalf of the Apache Commons team