/[Apache-SVN]
ViewVC logotype

Revision 1730888


Jump to revision: Previous Next
Author: jleroux
Date: Wed Feb 17 17:40:40 2016 UTC (8 years, 1 month ago)
Changed paths: 7
Log Message:
"Applied fix from trunk for revision: 1730882  " (conflict handled by hand)
------------------------------------------------------------------------
r1730882 | jleroux | 2016-02-17 18:29:40 +0100 (mer. 17 févr. 2016) | 10 lignes

In framework/base/lib/ updates Xalan from 2.7.1 to 2.7.2 because of CVE-2014-0107 (was fixed at XALANJ-2435) - https://issues.apache.org/jira/browse/OFBIZ-6905
This implies to update also Xerces from 2.9.1 to 2.11.0 and also xml-apis from 2.9.1 to 1.4.01 (2.9.1 was a wrong version number. It was actually part of the Xerces 2.9.1 package but I was unable to find the real version number then at https://xerces.apache.org/xerces2-j/releases.html)

Also updates Xalan from 27(?) to 2.7.2 in cmssite/template/docbook/extensions. I rendered https://localhost:8443/cmssite/cms/APACHE_OFBIZ_HTML w/o issues
	
Note: According to the DOM Level 3 specification and DOM Level 2 errata the createElementNS and createAttributeNS methods convert empty string namespaceURI to null. 

jleroux: though the tests pass I'm not sure all is covered...


------------------------------------------------------------------------


Changed paths

Path Details
Directoryofbiz/branches/release12.04/ modified , props changed
Directoryofbiz/branches/release12.04/framework/base/lib/xalan-2.7.1.jar deleted
Directoryofbiz/branches/release12.04/framework/base/lib/xalan-2.7.2.jar
(Copied from ofbiz/trunk/framework/base/lib/xalan-2.7.2.jar, r1730882)
added
Directoryofbiz/branches/release12.04/framework/base/lib/xercesImpl-2.11.0.jar
(Copied from ofbiz/trunk/framework/base/lib/xercesImpl-2.11.0.jar, r1730882)
added
Directoryofbiz/branches/release12.04/framework/base/lib/xercesImpl-2.9.1.jar deleted
Directoryofbiz/branches/release12.04/framework/base/lib/xml-apis-1.4.01.jar
(Copied from ofbiz/trunk/framework/base/lib/xml-apis-1.4.01.jar, r1730882)
added
Directoryofbiz/branches/release12.04/framework/base/lib/xml-apis-2.9.1.jar deleted

infrastructure at apache.org
ViewVC Help
Powered by ViewVC 1.1.26