Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 20 Oct 2008 13:22:20 +0200
From:      Gunther Mayer <gunther.mayer@googlemail.com>
To:        freebsd-security@freebsd.org
Subject:   Secure libxml2?
Message-ID:  <48FC69EC.9000609@gmail.com>

next in thread | raw e-mail | index | archive | help
Hi there,

We're using libxml2 and the version in ports (2.6.x) currently suffers 
from a rather serious security vulnerability already posted last Friday:

http://www.freebsd.org/ports/portaudit/d71da236-9a94-11dd-8f42-001c2514716c.html 


Yet there's no libxml2-2.7.x in ports as required by the above notice. 
So there's no solution other than compiling an up-to-date one by hand 
and that opens up a whole different can of worms regarding dependencies.

I emailed the official maintainer (gnome@freebsd.org) but am not holding 
my breath, chances are they won't even see my mail amongst all the spam 
they must be getting. So I'm wondering does anybody know what's going on 
or what I could do to get my systems secure?

Regards,

Gunther



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?48FC69EC.9000609>