Shibboleth Service Provider V2.6.0 now available

Takeshi NISHIMURA takeshi at nii.ac.jp
Tue Jul 5 04:19:53 EDT 2016


Thank you for this new release, Scott.

Is there any reason of not listing CVE-2016-4463 in "Advisory List" in
https://wiki.shibboleth.net/confluence/display/SHIB2/SecurityAdvisories
?

Sincerely,
Takeshi

On 2016/06/30 0:49, Cantor, Scott wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> The Shibboleth Project has released V2.6.0 of the Service Provider
> software, the first feature upgrade in several years.
>
> This release includes a permanent fix for the security issue
> described in the advisory last month [1], a number of other new
> features and bug fixes, and (on Windows) includes a new version
> of the Xerces XML parser that addresses a vulnerability disclosed
> earlier today [2].
>
> Please refer to the release notes [3] for a complete summary of
> important changes and a link to the complete list of issues addressed.
>
> Source code and the Windows installers are now available and RPMs will be
> produced over the course of the day, including an updated Xerces package
> for older platforms.
>
> [1] https://shibboleth.net/community/advisories/secadv_20160504.txt
> [2] http://xerces.apache.org/xerces-c/secadv/CVE-2016-4463.txt
> [3] https://wiki.shibboleth.net/confluence/x/QoFC


More information about the users mailing list