Shibboleth Service Provider V2.6.0 now available

Cantor, Scott cantor.2 at osu.edu
Fri Jul 1 15:24:48 EDT 2016


> Okay, I think I get this. So, you mentioned that RHEL7 and related should
> consider building from source if they don't want to wait for Redhat. For RHEL
> 6, is Xerces 3.0 not vulnerable?

Xerces 3.0 isn't used. I ship my own build of 3.1.

> That wasn't clear to me in the advisory. What
> I'm asking is: do RHEL 6 systems need to build Xerces-C from source if they
> want to fix this vulnerability before Redhat releases a fix? Or is just the latest
> Redhat 6 Xerces-C not involved in this vulnerability?

It's not involved because it's not used. It's vulnerable, but I don't depend on it.
 
> I'm just trying to figure out what to tell our RH6 admins here on campus.

Run yum update.

-- Scott



More information about the users mailing list