/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Contents of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log


Revision 8413 - (hide annotations) (download)
Wed Mar 26 12:40:34 2008 UTC (5 years, 2 months ago) by jamie-guest
File size: 11608 byte(s)
embedded-code-copies: added libarchive
1 nion 7695 Embedded code copies
2     ====================
3    
4 thijs 8078 This file collects source packages that embed code from other projects.
5     This is considered bad for fixing security flaws because the fix needs
6     to be applied in multiple source packages.
7 jmm-guest 1586
8 nion 7695 Format:
9     <srcpkg> (<optional comment about srcpkg>)
10     - <embedding srcpkg> <status> (<sort>; bug #<number>)
11     NOTE: optional comments about the linkage of the embedding srcpkg
12    
13 thijs 8078 status: version number fixing the embedded copy, <unfixed>, <removed>,
14     <itp> or <unknown> if the version number can not be determined
15 fw 8142 <unfixable> for unavoidable cases (e.g., forks that add real value)
16 nion 7828 sort: static (linking statically against a lib)
17     embed (embedding a copy of the library into another source package)
18 thijs 8078 fork (the package is not just embedding code but it is a fork and
19     thus might share parts of the source code)
20 fw 8142 old-version (the package is an older version of essentially
21     the same code)
22 nion 7828
23 thijs 8078 The srcpkg might be some string to identify the code if there is no
24     specific source package.
25 jmm-guest 1586
26 thijs 8078 Everything up to the next line is ignored.
27 stef-guest 7923 ---BEGIN
28 nion 7696 xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29 jmm-guest 7743 NOTE: Fixed packages link to poppler library unless otherwise noted
30 nion 7697 - gpdf <removed>
31     [sarge] - gpdf <unfixed>
32     NOTE: has been replaced by evince in etch
33     - pdftohtml <unknown>
34     [sarge] - pdftohtml <unfixed>
35     [etch] - pdftohtml <unfixed>
36     NOTE: has been replaced by poppler-utils
37 nion 7739 - kdegraphics <unfixed> (embed; bug #436164)
38 nion 7696 NOTE: the kpdf replacement in KDE 4 is using poppler
39 nion 7739 - tetex-bin 3.0-12 (embed)
40 jmm-guest 7743 - texlive-bin 2007-1 (embed)
41 nion 7696 NOTE: links to poppler
42 nion 7739 - koffice <unfixed> (embed; bug #436163)
43     - libextractor 0.5.12-1 (embed)
44 jmm-guest 7743 NOTE: libextractor is using its own pdf decoder now
45 nion 7739 - libextractor 0.5.12-1 (embed)
46     - pdfkit.framework 0.8-4 (embed)
47     - ipe <unfixed> (embed)
48 nion 7696 NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
49 nion 7739 - ruby-gnome2 <unknown> (embed)
50 nion 7696 NOTE: copy only present in source but links to poppler
51    
52 nion 7791 ppmd
53 nion 7755 - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55 thijs 8189 peercast
56     - gnome-peercast <unfixed> (embed)
57     NOTE: gnome-peercast may better be removed, see #466539
58    
59 nion 7791 silc-toolkit
60 nion 7740 - silc-client 1.1~beta6-1 (embed)
61 nion 6965
62 nion 7791 dietlibc
63 nion 7740 - ccontrol 0.9.1+20071204-1 (static)
64 nion 6967
65 nion 7791 libiax
66 nion 7740 - iaxmodem <unfixed> (embed)
67 nion 6969
68 nion 7787 zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
69     - dpkg <unfixed> (embed)
70     NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
71     - rsync <unfixed> (embed)
72     NOTE: somehow derived code base
73     - mono <unfixed> (embed)
74     TODO: check mozilla
75     - Linux kernels <unfixed> (embed)
76     - pvpgn 1.7.8-2 (embed)
77     - mrtg 2.12.2-1 (embed)
78     - rpm <unknown> (embed)
79 nion 7841 NOTE: pinged anibal since when rpm was fixed
80 jmm-guest 1586
81 nion 7788 libbz2
82     - dpkg <unfixed> (static)
83 stef-guest 5320
84 nion 7788 ekg
85     - centericq <unfixed> (embed)
86     - gaim <unfixed> (embed)
87     - pigdin <unfixed> (embed)(links dynamically against libgadu)
88     - kopete 4:3.3.2-5 (embed)
89     - kadu <unfixed> (embed)
90     - gadu <unfixed> (embed)
91     NOTE: g/kadu not packaged in Debian yet
92 jmm-guest 1586
93 nion 7791 xmlrpc (which package is the "origin" of this code?)
94 nion 7788 - drupal <unfixed> (embed)
95     - phpgroupware <unfixed> (embed)
96     - egroupware <unfixed> (embed)
97     - phpwiki (embed)
98     - php4 <unfixed> (embed)
99     TODO: check, php-pear, IIRC this was reorganized some weeks ago?
100 jmm-guest 1586
101 nion 7791 shtool (affects build-time only)
102     - mysql-ocaml <unfixed> (embed)
103     - php4 <unfixed> (embed)
104 jmm-guest 1588
105 nion 7791 mozilla source code
106     - mozilla-firefox <unfixed> (embed)
107     - mozilla-thunderbird
108     - firefox <removed>
109     [etch] - firefox <unfixed> (embed)
110     - thunderbird <removed>
111     [etch] - thunderbird <unfixed> (embed)
112     - iceweasel <unfixed> (embed)
113     - iceape <unfixed> (embed)
114     - icedove <unfixed> (embed)
115     - xulrunner <unfixed> (embed)
116     - nvu <removed> (embed)
117 jmm-guest 1588
118 nion 7791 xli
119     - xloadimage <unfixed> (embed)
120 jmm-guest 1588
121 nion 7827 lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
122     - openmotif <unfixed> (embed)
123     - xfree86/xorg <unfixed> (embed)
124     NOTE: in libxpm
125 jmm-guest 1588
126 nion 7827 kerberized apps with BSD origin
127     - krb4 <unfixed> (embed)
128     - krb5 <unfixed> (embed)
129     - heimdal <unfixed> (embed)
130 jmm-guest 1588
131 nion 7827 grip (which pkg is the origin?)
132     - libcdaudio
133     - grip
134     - gnome-vfs
135     TODO: check vfs2 as well
136 stef-guest 1608
137 nion 7827 fudforum
138     - phpgroupware-fudforum <unfixed> (embed)
139     - egroupware-fudforum <removed>
140     [sarge] - egroupware-fudforum <unfixed> (embed)
141 jmm-guest 1670
142 nion 7827 cvs
143     - gcvs <unfixed> (embed)
144     NOTE: see cvsunix/src in tarball
145 jmm-guest 1684
146 nion 7827 pcre
147     - python* <unfixed> (embed)
148     - php4 <unknown> (embed)
149     - analog 2:5.23-0woody1 (embed)
150     - libgoffice-1 <unfixed> (embed)
151     - vfu 4.06-4.1 (embed; bug #450754)
152     - tf5 5.0beta7-1 (embed)
153     - monotone <unfixed> (embed)
154     NOTE: this only affects versions >= 0.37
155     - glib <unfixed> (embed)
156     NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic
157     - apache2 2.0.53-4 (embed)
158     - exim4 4.10-0.srh20.12 (embed)
159     - yacas <unfixed> (embed)
160     NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
161     - gtamsanalyzer.app 0.42-5 (embed)
162 nion 8392 - tin <unknown> (embed)
163 jmm-guest 1758
164 nion 7827 tiff
165     - wxpythongtk <unfixed> (embed)
166     TODO: check, which debian pkg this is in
167 joeyh 1802
168 nion 7827 uudeview
169     - libconvert-uulib-perl <unfixed> (embed)
170 jmm-guest 1824
171 nion 7827 sqlite (not affected by security vulnerabilities so far)
172     - amarok <unfixed> (embed)
173     - monotone <unfixed> (embed)
174     - iceweasel <unfixed> (embed)
175 jmm-guest 1828
176 nion 7827 util-linux/mount
177     - loop-aes-utils <unfixed> (embed)
178     NOTE: contains code from util-linux' mount in the mount-aes-udeb
179 jmm-guest 2104
180 nion 7827 webmin
181     - usermin <unknown> (embed)
182     [sarge] - usermin <unfixed> (embed)
183 jmm-guest 2714
184 nion 7827 sylpheed
185 nion 7828 - sylpheed-claws <unfixed> (fork)
186 jmm-guest 2751
187 nion 7827 phpsysinfo
188     - egroupware <unfixed> (embed)
189     - phpgroupware <unfixed> (embed)
190 jmm-guest 2800
191 nion 7830 phpldapadmin
192 stef-guest 7923 [sarge] - egroupware <unfixed> (embed)
193 nion 7830 NOTE: removed from egroupware after sarge
194 jmm-guest 2800
195 nion 7830 chmlib
196     - kchmviewer <unknown> (embed)
197 jmm-guest 2800
198 nion 7830 libavcodec/libavformat (source: ffmpeg)
199     - mplayer <unfixed> (embed; bug #395252)
200     - xvidcap <unfixed> (embed)
201     - kino <unfixed> (static)
202     - vlc <unfixed> (static)
203     - smilutils <unfixed> (static)
204     - motion <unfixed> (static)
205     - gst-ffmpeg <unfixed> (embed)
206     - gstreamer0.10-ffmpeg <unfixed> (embed)
207     - xmovie <unfixed>
208 nion 7841 TODO: gimp-gap (potentially using ffmpeg code as well)
209 jmm-guest 2948
210 nion 7830 mad MPEG decoding lib
211     - mad <unfixed> (embed)
212     - xine-lib <unfixed> (embed)
213 jmm-guest 2948
214     libdts
215 nion 7840 - xine-lib <unfixed> (embed)
216 jmm-guest 2948
217     flac
218 nion 7840 - xine-lib <unfixed> (embed)
219 jmm-guest 2948
220 nion 7840 liba52
221     - a52dec <unfixed> (embed)
222     - xine-lib <unfixed> (embed)
223 jmm-guest 2948
224 nion 7840 libmpeg2
225     - mpeg2dec <unfixed> (embed)
226     - xine-lib <unfixed> (embed)
227 jmm-guest 2948
228 nion 7840 curl
229     - wget <unfixed> (embed)
230     NOTE: code for NTLM authentication
231 jmm-guest 3093
232 nion 7840 uw-imap
233     - pine <unfixed> (embed)
234     - alpine <unfixed> (embed)
235 jmm-guest 3320
236 nion 7840 imagemagick
237     - graphicsmagick <unfixed> (fork)
238 jmm-guest 3402
239 nion 7840 halibut
240     - nsis <unfixed> (embed)
241 micah 3537
242 nion 7840 libghttp
243     - hotway <unfixed> (embed)
244 micah 3537
245 nion 7840 libsndfile
246     - ardour <unfixed> (embed)
247 micah 3537
248 nion 7840 glibmm2.4
249     - ardour <unfixed> (embed)
250 nion 6869
251 nion 7840 libgnomecanvasmm2.6
252     - ardour <unfixed> (embed)
253 nion 6869
254 nion 7840 libsigc++-2.0
255     - ardour <unfixed> (embed)
256 nion 6869
257 nion 7840 soundtouch
258     - ardour <unfixed> (embed)
259 nion 6869
260 nion 7840 libmms
261     - xine-lib <unfixed> (embed)
262     - mimms <unfixed> (embed)
263 nion 6869
264 nion 7840 fckeditor
265 nion 8085 - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
266 nion 7840 - moin <unfixed> (embed; bug #452599)
267     - karrigell <unfixed> (embed; bug #452598)
268     - gforge-plugins-extra 4.6.99+svn6225-1 (embed)
269 stef-guest 4517
270 nion 7841 ipatlas (not packaged in Debian)
271     - moodle <unfixed> (embed)
272 jmm-guest 7383
273 nion 7841 libphp-phpmailer
274     - moodle <unfixed> (embed)
275 neilm 4838
276 nion 7841 htmlArea (not packaged in Debian)
277     - moodle <unfixed> (embed)
278    
279 nion 8175 giflib:
280     - wine <unfixed> (embed; bug #466181)
281    
282 nion 7841 bennu (not packaged in Debian)
283     - moodle <unfixed> (embed)
284    
285     smarty:
286 thijs 8342 - moodle <unfixed> (embed; bug #471158)
287     - gallery2 <unfixed> (embed; bug #471160)
288 nion 8361 - mahara 0.9.2-2 (embed; bug #471201)
289 thijs 8347 - gosa 2.4beta1-1 (embed; bug #471200)
290 nion 7841
291 nion 7840 TinyMCE
292     - wordpress <unfixed> (embed)
293     - moodle <unfixed> (embed)
294     - knowledgeroot <unfixed> (embed)
295     - joomla <itp> (bug #326398)
296 stef-guest 4517
297 nion 7840 scintilla
298     - scite <unfixed> (embed)
299     - qscintilla <unfixed> (embed)
300     - qscintilla2 <unfixed> (embed)
301     - geany <unfixed> (embed)
302 stef-guest 4706
303 nion 7840 libphp-adodb
304 stef-guest 7923 - moodle <unfixed> (embed)
305     NOTE: also AdoDB-XML Schema
306 nion 7840 - gallery2 <unfixed> (embed)
307     - phppgadmin <unfixed> (embed)
308     - egroupware <unfixed> (embed)
309     - phpwiki <unfixed> (embed)
310     - ipplan <unfixed> (embed)
311     - typo3 <unfixed> (embed)
312     - moodle <unfixed> (embed)
313     - cacti <unknown> (embed)
314     [sarge] - cacti <unfixed> (embed)
315     NOTE: dependency exists, but internal version is used
316 stef-guest 4706
317 nion 7840 gzip
318 nion 7841 - linux-kernel <unfixed> (embed)
319     NOTE: lib/inflate.c
320     - klibc <unfixed> (embed)
321     NOTE: based on linux-kernel gzip code
322     - busybox <unfixed> (embed)
323 micah 4767
324 nion 7841 neon
325     - cadaver <unfixed> (embed; bug #188381)
326     - gnome-vfs2 <unfixed> (embed; bug #395874)
327     - litmus <unfixed> (embed; #395875)
328     [sarge] - screem <unfixed> (embed)
329     - sitecopy <unfixed> (embed; bug #395876)
330 stef-guest 7923 [etch] - tla <unfixed> (embed; bug #395877)
331     [sarge] - tla <unfixed> (embed; bug #395877)
332 stef-guest 5319
333 nion 7841 libmodplug
334     - gst-plugins-bad0.10 <unfixed> (embed)
335 stef-guest 5320
336 nion 7841 libvncserver
337     - vino <unfixed> (embed)
338 stef-guest 5320
339 nion 7841 putty
340     - filezilla <unfixed> (embed)
341 stef-guest 5320
342 nion 7841 tinyxml (not packaged in Debian)
343     - filezilla <unfixed>
344 stef-guest 5320
345 nion 7841 gv
346     - evince <unfixed> (embed)
347     NOTE: ps/ tree from gv 3.5.8
348     - evince-gtk <unfixed> (embed)
349     NOTE: not packaged in Debian
350 stef-guest 5321
351 nion 7841 libXbae
352     [etch] - libpawlib2-lesstif <unfixed> (embed)
353     NOTE: from Cernlib
354 stef-guest 5321
355 nion 7841 libXaw
356 stef-guest 7924 [etch] - libpawlib2-lesstif
357 nion 7841 NOTE: from Cernlib
358     NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
359 stef-guest 5321
360 nion 7841 libgd2
361     - graphviz <unfixed> (embed)
362     NOTE: lib/gd seems to be 2.0.33
363 nion 8098 - wml <unfixed> (embed)
364     NOTE: derived from gd 1.6.3
365 stef-guest 5321
366 nion 7841 rar
367     - unrar-nonfree <unfixed> (embed)
368 stef-guest 5440
369 nion 7841 unrar-free (maybe this code is derived from the original rar, too?)
370     - clamav <unfixed> (embed)
371     NOTE: seems to be disabled in default config
372 stef-guest 5440
373 nion 7841 mplayer (DirectMedia Object loader)
374     - xine-lib <unfixed> (embed)
375     NOTE: src/libw32dll/
376     - vlc <unfixed> (embed)
377     NOTE: modules/codec/dmo/
378 stef-guest 5440
379 nion 7841 libwpd (WordPerfect converter)
380     - openoffice.org <unfixed> (embed)
381 alec-guest 5564
382 nion 7841 fsplib (http://sourceforge.net/projects/fsp/)
383     - gftp <unfixed> (embed)
384     NOTE: lib/fsplib version 0.3
385 keescook-guest 6298
386 nion 7841 librpcsecgss
387     - krb5 <unfixed> (embed)
388 keescook-guest 6498
389 nion 7841 jasper
390     - ghostscript <unfixed> (embed)
391     - gs-gpl <unfixed> (embed)
392 stef-guest 6985
393 nion 7841 libidn
394     - monotone <unfixed> (embed)
395 keescook-guest 7007
396 nion 7841 liblua
397     - monotone <unfixed> (embed)
398 micah 7134
399 nion 7841 libbotan
400     - montone <unfixed> (embed)
401 nion 7136
402 nion 7841 NetXX
403     - monotone <unfixed> (embed)
404 nion 7136
405 nion 7841 libgc
406     - mono <unfixed> (embed)
407 nion 7136
408 nion 7841 lzma
409     - p7zip <unfixed> (embed)
410 white 7203
411 nion 7841 lzo
412     - grub2 <unfixed> (embed)
413 jmm-guest 7212
414 nion 7927 yassl
415     - mysql-dfsg-5.0 <unfixed> (embed)
416    
417 nion 7841 pax code
418     - tar <unfixed> (embed)
419     - cpio <unfixed> (embed)
420 jmm-guest 7212
421 nion 7841 t1lib
422     - tetex-bin 2.0.2-1 (embed)
423     - texlive-bin <unknown> (embed)
424 thijs 7985
425     guichan
426     - boswars <unfixed> (embed)
427     NOTE: maintainer notified us, working on it
428    
429     tolua
430     - boswars <unfixed> (embed)
431     NOTE: maintainer notified us, working on it
432    
433     asio-dev
434     - luxrender <unfixed> (embed)
435     NOTE: maintainer notified us, working on it
436     NOTE: may be merged with boost "soon"
437    
438 nion 7995 xine-lib
439     - vlc <unfixed> (embed)
440     NOTE: only parts included in modules/access/rtsp
441 stef-guest 8075
442     netpbm
443     - tcl8.3 <unfixed> (embed)
444     - tcl8.4 <unfixed> (embed)
445     - tcl8.5 <unfixed> (embed)
446     NOTE: generic/tkImgGIF.c
447 fw 8143
448     tk8.5
449     - tk8.0 <removed> (old-version)
450     - tk8.3 <unfixed> (old-version)
451     - tk8.4 <unfixed> (old-version)
452     - perl-tk <unfixable> (fork)
453 nion 8280
454 nion 8281 samba
455 nion 8280 - mc <unfixed> (embed)
456     NOTE: maintainer is aware of this, currently searching a solution
457 micah 8337
458     plib1.8.4c2
459     - boson <unfixed> (fork)
460     NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
461 micah 8370
462     fribidi
463     - quesoglc <unfixed> (embed)
464    
465     glew
466     - quesoglc <unfixed> (embed)
467    
468     minorGems
469     - transcend <unfixed> (embed)
470     - cultivation <unfixed> (embed)
471 jamie-guest 8413
472     libarchive
473     - tar <unfixed> (embed)
474     NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher
475     - cpio <unfixed> (embed)
476     NOTE: cpio included in libarchive 2.2 and higher
477    

  ViewVC Help
Powered by ViewVC 1.1.5