Shibboleth Service Provider Security Advisory [2018-01-12]

Aaron Howell aaron.howell at deakin.edu.au
Fri Jan 12 16:06:44 EST 2018


On 13 Jan 2018, at 2:37 am, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:

While it is possible to determine whether one is already immune to this
bug, the installation of this patch is a simpler step, and strongly
encouraged.

Considering we will need to work out again how to build our own version of this package, so that Apache 2.4 won’t keep locking up on us (CPPXT-116<https://issues.shibboleth.net/jira/browse/CPPXT-116>) - working out if we are actually vulnerable might be the simpler step for us.

Could you please provide some details on this?

Cheers,
Aaron

Important Notice: The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete it and any attachments immediately and advise the sender by return email or telephone.

Deakin University does not warrant that this email and any attachments are error or virus free.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180112/d026bed6/attachment.html>


More information about the users mailing list