Shibboleth Service Provider V2.6.0 now available

Wessel, Keith kwessel at illinois.edu
Fri Jul 1 15:27:18 EDT 2016


Duh. Yes, I understand now. Sorry for being dense.

Thanks,
Keith


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Friday, July 01, 2016 2:25 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: Shibboleth Service Provider V2.6.0 now available

> Okay, I think I get this. So, you mentioned that RHEL7 and related should
> consider building from source if they don't want to wait for Redhat. For RHEL
> 6, is Xerces 3.0 not vulnerable?

Xerces 3.0 isn't used. I ship my own build of 3.1.

> That wasn't clear to me in the advisory. What
> I'm asking is: do RHEL 6 systems need to build Xerces-C from source if they
> want to fix this vulnerability before Redhat releases a fix? Or is just the latest
> Redhat 6 Xerces-C not involved in this vulnerability?

It's not involved because it's not used. It's vulnerable, but I don't depend on it.
 
> I'm just trying to figure out what to tell our RH6 admins here on campus.

Run yum update.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list