Shibboleth Service Provider V2.6.0 now available

Wessel, Keith kwessel at illinois.edu
Wed Jun 29 17:28:53 EDT 2016


Doesn't include xerces-c? It does when I yum search for it: xerces-c 3.0.1-20.el6.

Is that version not vulnerable?

Keith


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, June 29, 2016 4:26 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: Shibboleth Service Provider V2.6.0 now available

> I'm not finding anything on Redhat's site about their status of CVE-2016-4463.

The last two bugs took about 6 months and a month respectively. I have no idea what they will do.

> I know it was just announced, but does anyone know how they're
> categorizing this one, or if they've already addressed it for RHEL 6?

6 doesn't include this library.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list