On Tue, 2 Jul 2019, Jack Hill wrote: >> Apparently these symbols were never supposed to be exported: >> . However, there could >> be packages "in the wild" that uses these symbols and would silently >> break with the grafted Expat. >> >> IIUC the fix for CVE-2018-20843 is this commit: >> . >> >> I think it's better to graft a variant with only this patch to be on the >> safe side. Can you try that? > > Good idea. I didn't think to check. Yes, I can try to do that. > >> Could you also submit a second patch that adds GitHub as an additional >> download location for the regular Expat package? :-) > > I'll try that as well. I've prepared the two attached patches that I believe implement Marius's proposed solution. Thanks, Jack