Shibboleth Service Provider V2.6.0 now available
Wessel, Keith
kwessel at illinois.edu
Fri Jul 1 15:27:18 EDT 2016
Duh. Yes, I understand now. Sorry for being dense.
Thanks,
Keith
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Friday, July 01, 2016 2:25 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: Shibboleth Service Provider V2.6.0 now available
> Okay, I think I get this. So, you mentioned that RHEL7 and related should
> consider building from source if they don't want to wait for Redhat. For RHEL
> 6, is Xerces 3.0 not vulnerable?
Xerces 3.0 isn't used. I ship my own build of 3.1.
> That wasn't clear to me in the advisory. What
> I'm asking is: do RHEL 6 systems need to build Xerces-C from source if they
> want to fix this vulnerability before Redhat releases a fix? Or is just the latest
> Redhat 6 Xerces-C not involved in this vulnerability?
It's not involved because it's not used. It's vulnerable, but I don't depend on it.
> I'm just trying to figure out what to tell our RH6 admins here on campus.
Run yum update.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list