Shibboleth Service Provider V2.6.0 now available
Wessel, Keith
kwessel at illinois.edu
Fri Jul 1 15:15:52 EDT 2016
Okay, I think I get this. So, you mentioned that RHEL7 and related should consider building from source if they don't want to wait for Redhat. For RHEL 6, is Xerces 3.0 not vulnerable? That wasn't clear to me in the advisory. What I'm asking is: do RHEL 6 systems need to build Xerces-C from source if they want to fix this vulnerability before Redhat releases a fix? Or is just the latest Redhat 6 Xerces-C not involved in this vulnerability?
I'm just trying to figure out what to tell our RH6 admins here on campus.
Thanks,
Keith
'
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, June 30, 2016 8:51 AM
To: Shib Users <users at shibboleth.net>
Subject: RE: Shibboleth Service Provider V2.6.0 now available
> So, RHEL 6/CentOS 6 SP RPMs have xerces-c 3.1 built in then, and RHEL 6 folks
> don't need to worry about this one once they upgrade the SP?
Well, once you update Xerces. The SP doesn't enter into it.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list