dev-libs/xmlsec-1.2.14 has been released 25 minutes ago. It uses system libltdl instead of internal copy vulnerable to CVE-2009-3736 (see bug #295535).
dev-libs/xmlsec-1.2.14 is now in the tree.