Updating p5‑xml‑parser from 2.47 -> 2.49 fixes multiple CVEs:
- GH #39: Off‑by‑one heap buffer overflow in st_serial_stack growth check (CVE‑2006‑10003)
- GH #64: Buffer overflow in parse_stream when filehandle has :utf8 layer (CVE‑2006‑10002)
Reference: https://metacpan.org/release/TODDR/XML-Parser-2.48
However, the new release introduces additional dependencies into core:
- p5‑class‑inspector
- p5‑file‑sharedir‑install
- p5‑file‑sharedir
These packages are required only to support p5‑xml‑parser. At present, p5‑xml‑parser itself seems to be required only by intltool.
Action:
- In scope of CVE fixes, dependencies are introduced into core.
- We need to re‑evaluate whether p5‑xml‑parser should remain in pkgsrc‑core.
- If possible, extract it into pkgsrc‑system to avoid unnecessary expansion of core.
Tracking discussion here to avoid silent growth of pkgsrc‑core.
Updating p5‑xml‑parser from 2.47 -> 2.49 fixes multiple CVEs:
Reference: https://metacpan.org/release/TODDR/XML-Parser-2.48
However, the new release introduces additional dependencies into core:
These packages are required only to support p5‑xml‑parser. At present, p5‑xml‑parser itself seems to be required only by intltool.
Action:
Tracking discussion here to avoid silent growth of pkgsrc‑core.