Does CVE-2015-0235 (GHOST) affect Shibboleth SP?

Ian Rifkin irifkin at brandeis.edu
Sat Feb 7 19:14:36 EST 2015


I think the question is, if it's affected does anything within it have
glibc statically linked? Because if so, wouldn't yum updating alone
not fix it? It would have to be rebuilt from source, right?

When I patched my servers I also rebuilt any software I already
manually built on them.

Or am I misunderstanding the potential risk?

Another Ian

Sent from my iPhone

> On Feb 7, 2015, at 5:30 PM, Ian Young <ian at iay.org.uk> wrote:
>
>
>> On 7 Feb 2015, at 21:28, Takeshi NISHIMURA <takeshi at nii.ac.jp> wrote:
>>
>> Hi all,
>>
>> Does CVE-2015-0235 (GHOST) vulnerability affect Shibboleth SP?
>> I don't think so but I am not convinced.
>
> We don't know that it is affected, but it's hard to prove that it isn't: you would have to analyse all of the code in the stack (including things like libcurl, etc.) to be sure. So the safest approach is to patch for the vulnerability and restart the server, which you would almost certainly want to do on any potentially affected machine anyway.
>
>    -- Ian
>
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list