And expat has been recently found vulnerable, not sure if that makes udunits vulnerable but it's something to look at.
which version of udunits?
This is probably from Diego's tinderbox work, in which case it will have pulled the latest ~arch unmasked version. sci-libs/udunits-2.1.11 has a subdirectory named expat/, which at first glance appears to be a bundled copy of Expat.
Fixed in 2.1.11-r1