Does CVE-2015-0235 (GHOST) affect Shibboleth SP?

Ian Young ian at iay.org.uk
Sat Feb 7 17:30:08 EST 2015


> On 7 Feb 2015, at 21:28, Takeshi NISHIMURA <takeshi at nii.ac.jp> wrote:
> 
> Hi all,
> 
> Does CVE-2015-0235 (GHOST) vulnerability affect Shibboleth SP?
> I don't think so but I am not convinced.

We don't know that it is affected, but it's hard to prove that it isn't: you would have to analyse all of the code in the stack (including things like libcurl, etc.) to be sure. So the safest approach is to patch for the vulnerability and restart the server, which you would almost certainly want to do on any potentially affected machine anyway.

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20150207/6281ad27/attachment.bin 


More information about the users mailing list