/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Contents of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log


Revision 8337 - (hide annotations) (download)
Sat Mar 15 17:11:55 2008 UTC (5 years, 3 months ago) by micah
File size: 11121 byte(s)
boson embeds a forked plib
1 nion 7695 Embedded code copies
2     ====================
3    
4 thijs 8078 This file collects source packages that embed code from other projects.
5     This is considered bad for fixing security flaws because the fix needs
6     to be applied in multiple source packages.
7 jmm-guest 1586
8 nion 7695 Format:
9     <srcpkg> (<optional comment about srcpkg>)
10     - <embedding srcpkg> <status> (<sort>; bug #<number>)
11     NOTE: optional comments about the linkage of the embedding srcpkg
12    
13 thijs 8078 status: version number fixing the embedded copy, <unfixed>, <removed>,
14     <itp> or <unknown> if the version number can not be determined
15 fw 8142 <unfixable> for unavoidable cases (e.g., forks that add real value)
16 nion 7828 sort: static (linking statically against a lib)
17     embed (embedding a copy of the library into another source package)
18 thijs 8078 fork (the package is not just embedding code but it is a fork and
19     thus might share parts of the source code)
20 fw 8142 old-version (the package is an older version of essentially
21     the same code)
22 nion 7828
23 thijs 8078 The srcpkg might be some string to identify the code if there is no
24     specific source package.
25 jmm-guest 1586
26 thijs 8078 Everything up to the next line is ignored.
27 stef-guest 7923 ---BEGIN
28 nion 7696 xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29 jmm-guest 7743 NOTE: Fixed packages link to poppler library unless otherwise noted
30 nion 7697 - gpdf <removed>
31     [sarge] - gpdf <unfixed>
32     NOTE: has been replaced by evince in etch
33     - pdftohtml <unknown>
34     [sarge] - pdftohtml <unfixed>
35     [etch] - pdftohtml <unfixed>
36     NOTE: has been replaced by poppler-utils
37 nion 7739 - kdegraphics <unfixed> (embed; bug #436164)
38 nion 7696 NOTE: the kpdf replacement in KDE 4 is using poppler
39 nion 7739 - tetex-bin 3.0-12 (embed)
40 jmm-guest 7743 - texlive-bin 2007-1 (embed)
41 nion 7696 NOTE: links to poppler
42 nion 7739 - koffice <unfixed> (embed; bug #436163)
43     - libextractor 0.5.12-1 (embed)
44 jmm-guest 7743 NOTE: libextractor is using its own pdf decoder now
45 nion 7739 - libextractor 0.5.12-1 (embed)
46     - pdfkit.framework 0.8-4 (embed)
47     - ipe <unfixed> (embed)
48 nion 7696 NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
49 nion 7739 - ruby-gnome2 <unknown> (embed)
50 nion 7696 NOTE: copy only present in source but links to poppler
51    
52 nion 7791 ppmd
53 nion 7755 - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55 thijs 8189 peercast
56     - gnome-peercast <unfixed> (embed)
57     NOTE: gnome-peercast may better be removed, see #466539
58    
59 nion 7791 silc-toolkit
60 nion 7740 - silc-client 1.1~beta6-1 (embed)
61 nion 6965
62 nion 7791 dietlibc
63 nion 7740 - ccontrol 0.9.1+20071204-1 (static)
64 nion 6967
65 nion 7791 libiax
66 nion 7740 - iaxmodem <unfixed> (embed)
67 nion 6969
68 nion 7787 zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
69     - dpkg <unfixed> (embed)
70     NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
71     - rsync <unfixed> (embed)
72     NOTE: somehow derived code base
73     - mono <unfixed> (embed)
74     TODO: check mozilla
75     - Linux kernels <unfixed> (embed)
76     - pvpgn 1.7.8-2 (embed)
77     - mrtg 2.12.2-1 (embed)
78     - rpm <unknown> (embed)
79 nion 7841 NOTE: pinged anibal since when rpm was fixed
80 jmm-guest 1586
81 nion 7788 libbz2
82     - dpkg <unfixed> (static)
83 stef-guest 5320
84 nion 7788 ekg
85     - centericq <unfixed> (embed)
86     - gaim <unfixed> (embed)
87     - pigdin <unfixed> (embed)(links dynamically against libgadu)
88     - kopete 4:3.3.2-5 (embed)
89     - kadu <unfixed> (embed)
90     - gadu <unfixed> (embed)
91     NOTE: g/kadu not packaged in Debian yet
92 jmm-guest 1586
93 nion 7791 xmlrpc (which package is the "origin" of this code?)
94 nion 7788 - drupal <unfixed> (embed)
95     - phpgroupware <unfixed> (embed)
96     - egroupware <unfixed> (embed)
97     - phpwiki (embed)
98     - php4 <unfixed> (embed)
99     TODO: check, php-pear, IIRC this was reorganized some weeks ago?
100 jmm-guest 1586
101 nion 7791 shtool (affects build-time only)
102     - mysql-ocaml <unfixed> (embed)
103     - php4 <unfixed> (embed)
104 jmm-guest 1588
105 nion 7791 mozilla source code
106     - mozilla-firefox <unfixed> (embed)
107     - mozilla-thunderbird
108     - firefox <removed>
109     [etch] - firefox <unfixed> (embed)
110     - thunderbird <removed>
111     [etch] - thunderbird <unfixed> (embed)
112     - iceweasel <unfixed> (embed)
113     - iceape <unfixed> (embed)
114     - icedove <unfixed> (embed)
115     - xulrunner <unfixed> (embed)
116     - nvu <removed> (embed)
117 jmm-guest 1588
118 nion 7791 xli
119     - xloadimage <unfixed> (embed)
120 jmm-guest 1588
121 nion 7827 lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
122     - openmotif <unfixed> (embed)
123     - xfree86/xorg <unfixed> (embed)
124     NOTE: in libxpm
125 jmm-guest 1588
126 nion 7827 kerberized apps with BSD origin
127     - krb4 <unfixed> (embed)
128     - krb5 <unfixed> (embed)
129     - heimdal <unfixed> (embed)
130 jmm-guest 1588
131 nion 7827 grip (which pkg is the origin?)
132     - libcdaudio
133     - grip
134     - gnome-vfs
135     TODO: check vfs2 as well
136 stef-guest 1608
137 nion 7827 fudforum
138     - phpgroupware-fudforum <unfixed> (embed)
139     - egroupware-fudforum <removed>
140     [sarge] - egroupware-fudforum <unfixed> (embed)
141 jmm-guest 1670
142 nion 7827 cvs
143     - gcvs <unfixed> (embed)
144     NOTE: see cvsunix/src in tarball
145 jmm-guest 1684
146 nion 7827 pcre
147     - python* <unfixed> (embed)
148     - php4 <unknown> (embed)
149     - analog 2:5.23-0woody1 (embed)
150     - libgoffice-1 <unfixed> (embed)
151     - vfu 4.06-4.1 (embed; bug #450754)
152     - tf5 5.0beta7-1 (embed)
153     - monotone <unfixed> (embed)
154     NOTE: this only affects versions >= 0.37
155     - glib <unfixed> (embed)
156     NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic
157     - apache2 2.0.53-4 (embed)
158     - exim4 4.10-0.srh20.12 (embed)
159     - yacas <unfixed> (embed)
160     NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
161     - gtamsanalyzer.app 0.42-5 (embed)
162 jmm-guest 1758
163 nion 7827 tiff
164     - wxpythongtk <unfixed> (embed)
165     TODO: check, which debian pkg this is in
166 joeyh 1802
167 nion 7827 uudeview
168     - libconvert-uulib-perl <unfixed> (embed)
169 jmm-guest 1824
170 nion 7827 sqlite (not affected by security vulnerabilities so far)
171     - amarok <unfixed> (embed)
172     - monotone <unfixed> (embed)
173     - iceweasel <unfixed> (embed)
174 jmm-guest 1828
175 nion 7827 util-linux/mount
176     - loop-aes-utils <unfixed> (embed)
177     NOTE: contains code from util-linux' mount in the mount-aes-udeb
178 jmm-guest 2104
179 nion 7827 webmin
180     - usermin <unknown> (embed)
181     [sarge] - usermin <unfixed> (embed)
182 jmm-guest 2714
183 nion 7827 sylpheed
184 nion 7828 - sylpheed-claws <unfixed> (fork)
185 jmm-guest 2751
186 nion 7827 phpsysinfo
187     - egroupware <unfixed> (embed)
188     - phpgroupware <unfixed> (embed)
189 jmm-guest 2800
190 nion 7830 phpldapadmin
191 stef-guest 7923 [sarge] - egroupware <unfixed> (embed)
192 nion 7830 NOTE: removed from egroupware after sarge
193 jmm-guest 2800
194 nion 7830 chmlib
195     - kchmviewer <unknown> (embed)
196 jmm-guest 2800
197 nion 7830 libavcodec/libavformat (source: ffmpeg)
198     - mplayer <unfixed> (embed; bug #395252)
199     - xvidcap <unfixed> (embed)
200     - kino <unfixed> (static)
201     - vlc <unfixed> (static)
202     - smilutils <unfixed> (static)
203     - motion <unfixed> (static)
204     - gst-ffmpeg <unfixed> (embed)
205     - gstreamer0.10-ffmpeg <unfixed> (embed)
206     - xmovie <unfixed>
207 nion 7841 TODO: gimp-gap (potentially using ffmpeg code as well)
208 jmm-guest 2948
209 nion 7830 mad MPEG decoding lib
210     - mad <unfixed> (embed)
211     - xine-lib <unfixed> (embed)
212 jmm-guest 2948
213     libdts
214 nion 7840 - xine-lib <unfixed> (embed)
215 jmm-guest 2948
216     flac
217 nion 7840 - xine-lib <unfixed> (embed)
218 jmm-guest 2948
219 nion 7840 liba52
220     - a52dec <unfixed> (embed)
221     - xine-lib <unfixed> (embed)
222 jmm-guest 2948
223 nion 7840 libmpeg2
224     - mpeg2dec <unfixed> (embed)
225     - xine-lib <unfixed> (embed)
226 jmm-guest 2948
227 nion 7840 curl
228     - wget <unfixed> (embed)
229     NOTE: code for NTLM authentication
230 jmm-guest 3093
231 nion 7840 uw-imap
232     - pine <unfixed> (embed)
233     - alpine <unfixed> (embed)
234 jmm-guest 3320
235 nion 7840 imagemagick
236     - graphicsmagick <unfixed> (fork)
237 jmm-guest 3402
238 nion 7840 halibut
239     - nsis <unfixed> (embed)
240 micah 3537
241 nion 7840 libghttp
242     - hotway <unfixed> (embed)
243 micah 3537
244 nion 7840 libsndfile
245     - ardour <unfixed> (embed)
246 micah 3537
247 nion 7840 glibmm2.4
248     - ardour <unfixed> (embed)
249 nion 6869
250 nion 7840 libgnomecanvasmm2.6
251     - ardour <unfixed> (embed)
252 nion 6869
253 nion 7840 libsigc++-2.0
254     - ardour <unfixed> (embed)
255 nion 6869
256 nion 7840 soundtouch
257     - ardour <unfixed> (embed)
258 nion 6869
259 nion 7840 libmms
260     - xine-lib <unfixed> (embed)
261     - mimms <unfixed> (embed)
262 nion 6869
263 nion 7840 fckeditor
264 nion 8085 - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
265 nion 7840 - moin <unfixed> (embed; bug #452599)
266     - karrigell <unfixed> (embed; bug #452598)
267     - gforge-plugins-extra 4.6.99+svn6225-1 (embed)
268 stef-guest 4517
269 nion 7841 ipatlas (not packaged in Debian)
270     - moodle <unfixed> (embed)
271 jmm-guest 7383
272 nion 7841 libphp-phpmailer
273     - moodle <unfixed> (embed)
274 neilm 4838
275 nion 7841 htmlArea (not packaged in Debian)
276     - moodle <unfixed> (embed)
277    
278 nion 8175 giflib:
279     - wine <unfixed> (embed; bug #466181)
280    
281 nion 7841 bennu (not packaged in Debian)
282     - moodle <unfixed> (embed)
283    
284     smarty:
285     - moodle <unfixed> (embed)
286    
287 nion 7840 TinyMCE
288     - wordpress <unfixed> (embed)
289     - moodle <unfixed> (embed)
290     - knowledgeroot <unfixed> (embed)
291     - joomla <itp> (bug #326398)
292 stef-guest 4517
293 nion 7840 scintilla
294     - scite <unfixed> (embed)
295     - qscintilla <unfixed> (embed)
296     - qscintilla2 <unfixed> (embed)
297     - geany <unfixed> (embed)
298 stef-guest 4706
299 nion 7840 libphp-adodb
300 stef-guest 7923 - moodle <unfixed> (embed)
301     NOTE: also AdoDB-XML Schema
302 nion 7840 - gallery2 <unfixed> (embed)
303     - phppgadmin <unfixed> (embed)
304     - egroupware <unfixed> (embed)
305     - phpwiki <unfixed> (embed)
306     - ipplan <unfixed> (embed)
307     - typo3 <unfixed> (embed)
308     - moodle <unfixed> (embed)
309     - cacti <unknown> (embed)
310     [sarge] - cacti <unfixed> (embed)
311     NOTE: dependency exists, but internal version is used
312 stef-guest 4706
313 nion 7840 gzip
314 nion 7841 - linux-kernel <unfixed> (embed)
315     NOTE: lib/inflate.c
316     - klibc <unfixed> (embed)
317     NOTE: based on linux-kernel gzip code
318     - busybox <unfixed> (embed)
319 micah 4767
320 nion 7841 neon
321     - cadaver <unfixed> (embed; bug #188381)
322     - gnome-vfs2 <unfixed> (embed; bug #395874)
323     - litmus <unfixed> (embed; #395875)
324     [sarge] - screem <unfixed> (embed)
325     - sitecopy <unfixed> (embed; bug #395876)
326 stef-guest 7923 [etch] - tla <unfixed> (embed; bug #395877)
327     [sarge] - tla <unfixed> (embed; bug #395877)
328 stef-guest 5319
329 nion 7841 libmodplug
330     - gst-plugins-bad0.10 <unfixed> (embed)
331 stef-guest 5320
332 nion 7841 libvncserver
333     - vino <unfixed> (embed)
334 stef-guest 5320
335 nion 7841 putty
336     - filezilla <unfixed> (embed)
337 stef-guest 5320
338 nion 7841 tinyxml (not packaged in Debian)
339     - filezilla <unfixed>
340 stef-guest 5320
341 nion 7841 gv
342     - evince <unfixed> (embed)
343     NOTE: ps/ tree from gv 3.5.8
344     - evince-gtk <unfixed> (embed)
345     NOTE: not packaged in Debian
346 stef-guest 5321
347 nion 7841 libXbae
348     [etch] - libpawlib2-lesstif <unfixed> (embed)
349     NOTE: from Cernlib
350 stef-guest 5321
351 nion 7841 libXaw
352 stef-guest 7924 [etch] - libpawlib2-lesstif
353 nion 7841 NOTE: from Cernlib
354     NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
355 stef-guest 5321
356 nion 7841 libgd2
357     - graphviz <unfixed> (embed)
358     NOTE: lib/gd seems to be 2.0.33
359 nion 8098 - wml <unfixed> (embed)
360     NOTE: derived from gd 1.6.3
361 stef-guest 5321
362 nion 7841 rar
363     - unrar-nonfree <unfixed> (embed)
364 stef-guest 5440
365 nion 7841 unrar-free (maybe this code is derived from the original rar, too?)
366     - clamav <unfixed> (embed)
367     NOTE: seems to be disabled in default config
368 stef-guest 5440
369 nion 7841 mplayer (DirectMedia Object loader)
370     - xine-lib <unfixed> (embed)
371     NOTE: src/libw32dll/
372     - vlc <unfixed> (embed)
373     NOTE: modules/codec/dmo/
374 stef-guest 5440
375 nion 7841 libwpd (WordPerfect converter)
376     - openoffice.org <unfixed> (embed)
377 alec-guest 5564
378 nion 7841 fsplib (http://sourceforge.net/projects/fsp/)
379     - gftp <unfixed> (embed)
380     NOTE: lib/fsplib version 0.3
381 keescook-guest 6298
382 nion 7841 librpcsecgss
383     - krb5 <unfixed> (embed)
384 keescook-guest 6498
385 nion 7841 jasper
386     - ghostscript <unfixed> (embed)
387     - gs-gpl <unfixed> (embed)
388 stef-guest 6985
389 nion 7841 libidn
390     - monotone <unfixed> (embed)
391 keescook-guest 7007
392 nion 7841 liblua
393     - monotone <unfixed> (embed)
394 micah 7134
395 nion 7841 libbotan
396     - montone <unfixed> (embed)
397 nion 7136
398 nion 7841 NetXX
399     - monotone <unfixed> (embed)
400 nion 7136
401 nion 7841 libgc
402     - mono <unfixed> (embed)
403 nion 7136
404 nion 7841 lzma
405     - p7zip <unfixed> (embed)
406 white 7203
407 nion 7841 lzo
408     - grub2 <unfixed> (embed)
409 jmm-guest 7212
410 nion 7927 yassl
411     - mysql-dfsg-5.0 <unfixed> (embed)
412    
413 nion 7841 pax code
414     - tar <unfixed> (embed)
415     - cpio <unfixed> (embed)
416 jmm-guest 7212
417 nion 7841 t1lib
418     - tetex-bin 2.0.2-1 (embed)
419     - texlive-bin <unknown> (embed)
420 thijs 7985
421     guichan
422     - boswars <unfixed> (embed)
423     NOTE: maintainer notified us, working on it
424    
425     tolua
426     - boswars <unfixed> (embed)
427     NOTE: maintainer notified us, working on it
428    
429     asio-dev
430     - luxrender <unfixed> (embed)
431     NOTE: maintainer notified us, working on it
432     NOTE: may be merged with boost "soon"
433    
434 nion 7995 xine-lib
435     - vlc <unfixed> (embed)
436     NOTE: only parts included in modules/access/rtsp
437 stef-guest 8075
438     netpbm
439     - tcl8.3 <unfixed> (embed)
440     - tcl8.4 <unfixed> (embed)
441     - tcl8.5 <unfixed> (embed)
442     NOTE: generic/tkImgGIF.c
443 fw 8143
444     tk8.5
445     - tk8.0 <removed> (old-version)
446     - tk8.3 <unfixed> (old-version)
447     - tk8.4 <unfixed> (old-version)
448     - perl-tk <unfixable> (fork)
449 nion 8280
450 nion 8281 samba
451 nion 8280 - mc <unfixed> (embed)
452     NOTE: maintainer is aware of this, currently searching a solution
453 micah 8337
454     plib1.8.4c2
455     - boson <unfixed> (fork)
456     NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar

  ViewVC Help
Powered by ViewVC 1.1.5