Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 271133

Summary: dev-libs/dbxml depends on <dev-libs/xerces-c-3
Product: Gentoo Linux Reporter: Mark Loeser (RETIRED) <halcy0n>
Component: New packagesAssignee: Tiziano Müller (RETIRED) <dev-zero>
Status: RESOLVED CANTFIX    
Severity: normal    
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 271131    

Description Mark Loeser (RETIRED) gentoo-dev 2009-05-24 20:55:04 UTC
Ebuilds for this package have an explicit dependency on a version of xerces-c
which is less than 3.0.0.  All of these ebuilds must be fixed since earlier
versions of xerces-c have a security vulnerability, and those versions of
xerces-c need to be removed from the tree or hard-masked.

dev-libs/dbxml/dbxml-2.4.13.2.ebuild:	=dev-libs/xerces-c-2.8*
dev-libs/dbxml/dbxml-2.4.16.1.ebuild:	=dev-libs/xerces-c-2.8*
Comment 1 Tiziano Müller (RETIRED) gentoo-dev 2009-05-24 21:02:52 UTC
Forum entry about it at upstream here:
http://forums.oracle.com/forums/thread.jspa?threadID=904180&tstart=0

Until upstream releases a new version with xerces-c-3 support there's nothing we can do.