pkgsrc/devel/apache-maven/distinfo
yyamano 5cf299f401 Update apache maven to 3.0.5.
http://maven.apache.org/docs/3.0.5/release-notes.html

Apache Maven 3.0.5 is a maintenance release to fix a security
issue CVE-2013-0253 Apache Maven 3.0.4

http://maven.apache.org/security.html

CVE-2013-0253 Apache Maven 3.0.4

Apache Maven 3.0.4 (with Apache Maven Wagon 2.1) has
introduced a non-secure SSL mode by default. This mode
disables all SSL certificate checking, including: host
name verification , date validity, and certificate chain.
Not validating the certificate introduces the possibility
of a man-in-the-middle attack.

All users are recommended to upgrade to Apache Maven 3.0.5
and Apache Maven Wagon 2.4.
2013-03-03 16:53:42 +00:00

7 lines
406 B
Text

$NetBSD: distinfo,v 1.6 2013/03/03 16:53:42 yyamano Exp $
SHA1 (apache-maven-3.0.5-bin.tar.gz) = aecc0d3d67732939c0056d4a0d8510483ee1167e
RMD160 (apache-maven-3.0.5-bin.tar.gz) = 05b877ea0f1880ad62b48a436658ba70cce94b73
Size (apache-maven-3.0.5-bin.tar.gz) = 5144659 bytes
SHA1 (patch-bin_m2.conf) = e0d2d7442fd86e539d73c1cdb6449d9c8b412122
SHA1 (patch-bin_mvn) = 1b14289cfc53b0fd6f9a2a85b0d26bcdbb8f56b2