Does CVE-2015-0235 (GHOST) affect Shibboleth SP?
Ian Young
ian at iay.org.uk
Sun Feb 8 03:46:18 EST 2015
> On 8 Feb 2015, at 00:14, Ian Rifkin <irifkin at brandeis.edu> wrote:
>
> I think the question is, if it's affected does anything within it have
> glibc statically linked? Because if so, wouldn't yum updating alone
> not fix it? It would have to be rebuilt from source, right?
That's a good point. On the yum-based systems it's fairly rare to statically link things and I'm fairly sure we don't statically link any of our components. So just "yum update" and a reboot to make sure running processes are replaced should be sufficient.
Obviously if you have manually built Shibboleth yourself and gone for static linking for some reason, you'd need to rebuild after updating glibc, but that sounds like a really rare situation to me.
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20150208/50ae3334/attachment-0001.bin
More information about the users
mailing list