/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Contents of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log


Revision 8700 - (hide annotations) (download)
Sun May 4 11:32:24 2008 UTC (5 years, 1 month ago) by thijs
File size: 11850 byte(s)
abiword embeds wv
1 nion 7695 Embedded code copies
2     ====================
3    
4 thijs 8078 This file collects source packages that embed code from other projects.
5     This is considered bad for fixing security flaws because the fix needs
6     to be applied in multiple source packages.
7 jmm-guest 1586
8 nion 7695 Format:
9     <srcpkg> (<optional comment about srcpkg>)
10     - <embedding srcpkg> <status> (<sort>; bug #<number>)
11     NOTE: optional comments about the linkage of the embedding srcpkg
12    
13 thijs 8078 status: version number fixing the embedded copy, <unfixed>, <removed>,
14     <itp> or <unknown> if the version number can not be determined
15 fw 8142 <unfixable> for unavoidable cases (e.g., forks that add real value)
16 nion 7828 sort: static (linking statically against a lib)
17     embed (embedding a copy of the library into another source package)
18 thijs 8078 fork (the package is not just embedding code but it is a fork and
19     thus might share parts of the source code)
20 fw 8142 old-version (the package is an older version of essentially
21     the same code)
22 nion 7828
23 thijs 8078 The srcpkg might be some string to identify the code if there is no
24     specific source package.
25 jmm-guest 1586
26 thijs 8078 Everything up to the next line is ignored.
27 stef-guest 7923 ---BEGIN
28 nion 7696 xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29 jmm-guest 7743 NOTE: Fixed packages link to poppler library unless otherwise noted
30 nion 7697 - gpdf <removed>
31     [sarge] - gpdf <unfixed>
32     NOTE: has been replaced by evince in etch
33     - pdftohtml <unknown>
34     [sarge] - pdftohtml <unfixed>
35     [etch] - pdftohtml <unfixed>
36     NOTE: has been replaced by poppler-utils
37 nion 7739 - kdegraphics <unfixed> (embed; bug #436164)
38 nion 7696 NOTE: the kpdf replacement in KDE 4 is using poppler
39 nion 7739 - tetex-bin 3.0-12 (embed)
40 jmm-guest 7743 - texlive-bin 2007-1 (embed)
41 nion 7696 NOTE: links to poppler
42 nion 7739 - koffice <unfixed> (embed; bug #436163)
43     - libextractor 0.5.12-1 (embed)
44 jmm-guest 7743 NOTE: libextractor is using its own pdf decoder now
45 nion 7739 - libextractor 0.5.12-1 (embed)
46     - pdfkit.framework 0.8-4 (embed)
47     - ipe <unfixed> (embed)
48 nion 7696 NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
49 nion 7739 - ruby-gnome2 <unknown> (embed)
50 nion 7696 NOTE: copy only present in source but links to poppler
51    
52 nion 7791 ppmd
53 nion 7755 - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55 thijs 8189 peercast
56     - gnome-peercast <unfixed> (embed)
57     NOTE: gnome-peercast may better be removed, see #466539
58    
59 nion 7791 silc-toolkit
60 nion 7740 - silc-client 1.1~beta6-1 (embed)
61 nion 6965
62 nion 7791 dietlibc
63 nion 7740 - ccontrol 0.9.1+20071204-1 (static)
64 nion 6967
65 nion 7791 libiax
66 nion 7740 - iaxmodem <unfixed> (embed)
67 nion 6969
68 nion 7787 zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
69     - dpkg <unfixed> (embed)
70     NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
71     - rsync <unfixed> (embed)
72     NOTE: somehow derived code base
73     - mono <unfixed> (embed)
74     TODO: check mozilla
75     - Linux kernels <unfixed> (embed)
76     - pvpgn 1.7.8-2 (embed)
77     - mrtg 2.12.2-1 (embed)
78     - rpm <unknown> (embed)
79 nion 7841 NOTE: pinged anibal since when rpm was fixed
80 jmm-guest 1586
81 nion 7788 libbz2
82     - dpkg <unfixed> (static)
83 stef-guest 5320
84 nion 7788 ekg
85     - centericq <unfixed> (embed)
86     - gaim <unfixed> (embed)
87     - pigdin <unfixed> (embed)(links dynamically against libgadu)
88     - kopete 4:3.3.2-5 (embed)
89     - kadu <unfixed> (embed)
90     - gadu <unfixed> (embed)
91     NOTE: g/kadu not packaged in Debian yet
92 jmm-guest 1586
93 nion 7791 xmlrpc (which package is the "origin" of this code?)
94 nion 7788 - drupal <unfixed> (embed)
95     - phpgroupware <unfixed> (embed)
96     - egroupware <unfixed> (embed)
97     - phpwiki (embed)
98     - php4 <unfixed> (embed)
99     TODO: check, php-pear, IIRC this was reorganized some weeks ago?
100 jmm-guest 1586
101 nion 7791 shtool (affects build-time only)
102     - mysql-ocaml <unfixed> (embed)
103     - php4 <unfixed> (embed)
104 jmm-guest 1588
105 nion 7791 mozilla source code
106     - mozilla-firefox <unfixed> (embed)
107     - mozilla-thunderbird
108     - firefox <removed>
109     [etch] - firefox <unfixed> (embed)
110     - thunderbird <removed>
111     [etch] - thunderbird <unfixed> (embed)
112     - iceweasel <unfixed> (embed)
113     - iceape <unfixed> (embed)
114     - icedove <unfixed> (embed)
115     - xulrunner <unfixed> (embed)
116     - nvu <removed> (embed)
117 jmm-guest 1588
118 nion 7791 xli
119     - xloadimage <unfixed> (embed)
120 jmm-guest 1588
121 nion 7827 lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
122     - openmotif <unfixed> (embed)
123     - xfree86/xorg <unfixed> (embed)
124     NOTE: in libxpm
125 jmm-guest 1588
126 nion 7827 kerberized apps with BSD origin
127     - krb4 <unfixed> (embed)
128     - krb5 <unfixed> (embed)
129     - heimdal <unfixed> (embed)
130 jmm-guest 1588
131 nion 7827 grip (which pkg is the origin?)
132     - libcdaudio
133     - grip
134     - gnome-vfs
135     TODO: check vfs2 as well
136 stef-guest 1608
137 nion 7827 fudforum
138     - phpgroupware-fudforum <unfixed> (embed)
139     - egroupware-fudforum <removed>
140     [sarge] - egroupware-fudforum <unfixed> (embed)
141 jmm-guest 1670
142 nion 7827 cvs
143     - gcvs <unfixed> (embed)
144     NOTE: see cvsunix/src in tarball
145 jmm-guest 1684
146 nion 7827 pcre
147     - python* <unfixed> (embed)
148     - php4 <unknown> (embed)
149     - analog 2:5.23-0woody1 (embed)
150     - libgoffice-1 <unfixed> (embed)
151     - vfu 4.06-4.1 (embed; bug #450754)
152     - tf5 5.0beta7-1 (embed)
153     - monotone <unfixed> (embed)
154     NOTE: this only affects versions >= 0.37
155     - glib <unfixed> (embed)
156     NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic
157     - apache2 2.0.53-4 (embed)
158     - exim4 4.10-0.srh20.12 (embed)
159     - yacas <unfixed> (embed)
160     NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
161     - gtamsanalyzer.app 0.42-5 (embed)
162 nion 8392 - tin <unknown> (embed)
163 jmm-guest 1758
164 nion 7827 tiff
165 nion 8587 - wxwindows2.4 2.2.1 (embed)
166 joeyh 1802
167 nion 7827 uudeview
168     - libconvert-uulib-perl <unfixed> (embed)
169 jmm-guest 1824
170 nion 7827 sqlite (not affected by security vulnerabilities so far)
171     - amarok <unfixed> (embed)
172     - monotone <unfixed> (embed)
173     - iceweasel <unfixed> (embed)
174 jmm-guest 1828
175 nion 7827 util-linux/mount
176     - loop-aes-utils <unfixed> (embed)
177     NOTE: contains code from util-linux' mount in the mount-aes-udeb
178 jmm-guest 2104
179 nion 7827 webmin
180     - usermin <unknown> (embed)
181     [sarge] - usermin <unfixed> (embed)
182 jmm-guest 2714
183 nion 7827 sylpheed
184 nion 7828 - sylpheed-claws <unfixed> (fork)
185 jmm-guest 2751
186 nion 7827 phpsysinfo
187     - egroupware <unfixed> (embed)
188     - phpgroupware <unfixed> (embed)
189 jmm-guest 2800
190 nion 7830 phpldapadmin
191 stef-guest 7923 [sarge] - egroupware <unfixed> (embed)
192 nion 7830 NOTE: removed from egroupware after sarge
193 jmm-guest 2800
194 nion 7830 chmlib
195     - kchmviewer <unknown> (embed)
196 jmm-guest 2800
197 nion 7830 libavcodec/libavformat (source: ffmpeg)
198     - mplayer <unfixed> (embed; bug #395252)
199     - xvidcap <unfixed> (embed)
200     - kino <unfixed> (static)
201     - vlc <unfixed> (static)
202     - smilutils <unfixed> (static)
203     - motion <unfixed> (static)
204     - gst-ffmpeg <unfixed> (embed)
205     - gstreamer0.10-ffmpeg <unfixed> (embed)
206     - xmovie <unfixed>
207 nion 7841 TODO: gimp-gap (potentially using ffmpeg code as well)
208 jmm-guest 2948
209 nion 7830 mad MPEG decoding lib
210     - mad <unfixed> (embed)
211     - xine-lib <unfixed> (embed)
212 jmm-guest 2948
213     libdts
214 nion 7840 - xine-lib <unfixed> (embed)
215 jmm-guest 2948
216     flac
217 nion 7840 - xine-lib <unfixed> (embed)
218 jmm-guest 2948
219 nion 7840 liba52
220     - a52dec <unfixed> (embed)
221     - xine-lib <unfixed> (embed)
222 jmm-guest 2948
223 nion 7840 libmpeg2
224     - mpeg2dec <unfixed> (embed)
225     - xine-lib <unfixed> (embed)
226 jmm-guest 2948
227 nion 7840 curl
228     - wget <unfixed> (embed)
229     NOTE: code for NTLM authentication
230 jmm-guest 3093
231 nion 7840 uw-imap
232     - pine <unfixed> (embed)
233     - alpine <unfixed> (embed)
234 jmm-guest 3320
235 nion 7840 imagemagick
236     - graphicsmagick <unfixed> (fork)
237 jmm-guest 3402
238 nion 7840 halibut
239     - nsis <unfixed> (embed)
240 micah 3537
241 nion 7840 libghttp
242     - hotway <unfixed> (embed)
243 micah 3537
244 nion 7840 libsndfile
245     - ardour <unfixed> (embed)
246 micah 3537
247 nion 7840 glibmm2.4
248     - ardour <unfixed> (embed)
249 nion 6869
250 nion 7840 libgnomecanvasmm2.6
251     - ardour <unfixed> (embed)
252 nion 6869
253 nion 7840 libsigc++-2.0
254     - ardour <unfixed> (embed)
255 nion 6869
256 nion 7840 soundtouch
257     - ardour <unfixed> (embed)
258 nion 6869
259 nion 7840 libmms
260     - xine-lib <unfixed> (embed)
261     - mimms <unfixed> (embed)
262 nion 6869
263 nion 7840 fckeditor
264 nion 8085 - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
265 nion 7840 - moin <unfixed> (embed; bug #452599)
266     - karrigell <unfixed> (embed; bug #452598)
267     - gforge-plugins-extra 4.6.99+svn6225-1 (embed)
268 stef-guest 4517
269 nion 7841 ipatlas (not packaged in Debian)
270     - moodle <unfixed> (embed)
271 jmm-guest 7383
272 nion 7841 libphp-phpmailer
273     - moodle <unfixed> (embed)
274 neilm 4838
275 nion 7841 htmlArea (not packaged in Debian)
276     - moodle <unfixed> (embed)
277    
278 nion 8175 giflib:
279     - wine <unfixed> (embed; bug #466181)
280    
281 nion 7841 bennu (not packaged in Debian)
282     - moodle <unfixed> (embed)
283    
284     smarty:
285 thijs 8342 - moodle <unfixed> (embed; bug #471158)
286     - gallery2 <unfixed> (embed; bug #471160)
287 nion 8361 - mahara 0.9.2-2 (embed; bug #471201)
288 thijs 8347 - gosa 2.4beta1-1 (embed; bug #471200)
289 nion 7841
290 nion 7840 TinyMCE
291     - wordpress <unfixed> (embed)
292     - moodle <unfixed> (embed)
293     - knowledgeroot <unfixed> (embed)
294     - joomla <itp> (bug #326398)
295 stef-guest 4517
296 nion 7840 scintilla
297     - scite <unfixed> (embed)
298     - qscintilla <unfixed> (embed)
299     - qscintilla2 <unfixed> (embed)
300     - geany <unfixed> (embed)
301 stef-guest 4706
302 nion 7840 libphp-adodb
303 stef-guest 7923 - moodle <unfixed> (embed)
304     NOTE: also AdoDB-XML Schema
305 nion 7840 - gallery2 <unfixed> (embed)
306     - phppgadmin <unfixed> (embed)
307     - egroupware <unfixed> (embed)
308     - phpwiki <unfixed> (embed)
309     - ipplan <unfixed> (embed)
310     - typo3 <unfixed> (embed)
311     - moodle <unfixed> (embed)
312     - cacti <unknown> (embed)
313     [sarge] - cacti <unfixed> (embed)
314     NOTE: dependency exists, but internal version is used
315 stef-guest 4706
316 nion 7840 gzip
317 nion 7841 - linux-kernel <unfixed> (embed)
318     NOTE: lib/inflate.c
319     - klibc <unfixed> (embed)
320     NOTE: based on linux-kernel gzip code
321     - busybox <unfixed> (embed)
322 micah 4767
323 nion 7841 neon
324     - cadaver <unfixed> (embed; bug #188381)
325     - gnome-vfs2 <unfixed> (embed; bug #395874)
326     - litmus <unfixed> (embed; #395875)
327     [sarge] - screem <unfixed> (embed)
328     - sitecopy <unfixed> (embed; bug #395876)
329 stef-guest 7923 [etch] - tla <unfixed> (embed; bug #395877)
330     [sarge] - tla <unfixed> (embed; bug #395877)
331 stef-guest 5319
332 nion 7841 libmodplug
333     - gst-plugins-bad0.10 <unfixed> (embed)
334 stef-guest 5320
335 nion 7841 libvncserver
336     - vino <unfixed> (embed)
337 stef-guest 5320
338 nion 7841 putty
339     - filezilla <unfixed> (embed)
340 stef-guest 5320
341 nion 7841 tinyxml (not packaged in Debian)
342     - filezilla <unfixed>
343 stef-guest 5320
344 nion 7841 gv
345     - evince <unfixed> (embed)
346     NOTE: ps/ tree from gv 3.5.8
347     - evince-gtk <unfixed> (embed)
348     NOTE: not packaged in Debian
349 stef-guest 5321
350 nion 7841 libXbae
351     [etch] - libpawlib2-lesstif <unfixed> (embed)
352     NOTE: from Cernlib
353 stef-guest 5321
354 nion 7841 libXaw
355 stef-guest 7924 [etch] - libpawlib2-lesstif
356 nion 7841 NOTE: from Cernlib
357     NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
358 stef-guest 5321
359 nion 7841 libgd2
360     - graphviz <unfixed> (embed)
361     NOTE: lib/gd seems to be 2.0.33
362 nion 8098 - wml <unfixed> (embed)
363     NOTE: derived from gd 1.6.3
364 stef-guest 5321
365 nion 7841 rar
366     - unrar-nonfree <unfixed> (embed)
367 stef-guest 5440
368 nion 7841 unrar-free (maybe this code is derived from the original rar, too?)
369     - clamav <unfixed> (embed)
370     NOTE: seems to be disabled in default config
371 stef-guest 5440
372 nion 7841 mplayer (DirectMedia Object loader)
373     - xine-lib <unfixed> (embed)
374     NOTE: src/libw32dll/
375     - vlc <unfixed> (embed)
376     NOTE: modules/codec/dmo/
377 stef-guest 5440
378 nion 7841 libwpd (WordPerfect converter)
379     - openoffice.org <unfixed> (embed)
380 alec-guest 5564
381 nion 7841 fsplib (http://sourceforge.net/projects/fsp/)
382     - gftp <unfixed> (embed)
383     NOTE: lib/fsplib version 0.3
384 keescook-guest 6298
385 nion 7841 librpcsecgss
386     - krb5 <unfixed> (embed)
387 keescook-guest 6498
388 nion 7841 jasper
389     - ghostscript <unfixed> (embed)
390     - gs-gpl <unfixed> (embed)
391 stef-guest 6985
392 nion 7841 libidn
393     - monotone <unfixed> (embed)
394 keescook-guest 7007
395 nion 7841 liblua
396     - monotone <unfixed> (embed)
397 micah 7134
398 nion 7841 libbotan
399     - montone <unfixed> (embed)
400 nion 7136
401 nion 7841 NetXX
402     - monotone <unfixed> (embed)
403 nion 7136
404 nion 7841 libgc
405     - mono <unfixed> (embed)
406 nion 7136
407 nion 7841 lzma
408     - p7zip <unfixed> (embed)
409 white 7203
410 nion 7841 lzo
411     - grub2 <unfixed> (embed)
412 jmm-guest 7212
413 nion 7927 yassl
414     - mysql-dfsg-5.0 <unfixed> (embed)
415    
416 nion 7841 pax code
417     - tar <unfixed> (embed)
418     - cpio <unfixed> (embed)
419 jmm-guest 7212
420 nion 7841 t1lib
421     - tetex-bin 2.0.2-1 (embed)
422     - texlive-bin <unknown> (embed)
423 thijs 7985
424     guichan
425     - boswars <unfixed> (embed)
426     NOTE: maintainer notified us, working on it
427    
428     tolua
429     - boswars <unfixed> (embed)
430     NOTE: maintainer notified us, working on it
431    
432     asio-dev
433     - luxrender <unfixed> (embed)
434     NOTE: maintainer notified us, working on it
435     NOTE: may be merged with boost "soon"
436    
437 nion 7995 xine-lib
438     - vlc <unfixed> (embed)
439     NOTE: only parts included in modules/access/rtsp
440 stef-guest 8075
441     netpbm
442     - tcl8.3 <unfixed> (embed)
443     - tcl8.4 <unfixed> (embed)
444     - tcl8.5 <unfixed> (embed)
445     NOTE: generic/tkImgGIF.c
446 fw 8143
447     tk8.5
448     - tk8.0 <removed> (old-version)
449     - tk8.3 <unfixed> (old-version)
450     - tk8.4 <unfixed> (old-version)
451     - perl-tk <unfixable> (fork)
452 nion 8280
453 nion 8281 samba
454 nion 8280 - mc <unfixed> (embed)
455     NOTE: maintainer is aware of this, currently searching a solution
456 micah 8337
457     plib1.8.4c2
458     - boson <unfixed> (fork)
459     NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
460 micah 8370
461     fribidi
462     - quesoglc <unfixed> (embed)
463    
464     glew
465     - quesoglc <unfixed> (embed)
466    
467     minorGems
468     - transcend <unfixed> (embed)
469     - cultivation <unfixed> (embed)
470 jamie-guest 8413
471     libarchive
472     - tar <unfixed> (embed)
473 jamie-guest 8438 NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
474 jamie-guest 8413 - cpio <unfixed> (embed)
475 jamie-guest 8438 NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
476 jamie-guest 8413
477 nion 8523 webkit
478     - qt4-x11 <unfixed> (embed)
479 white 8694
480     ftgl
481     - blender 2.45+r14660-1 (embed)
482     NOTE: Once the above version is released, it will be fixed
483 thijs 8700
484     wv
485     - abiword <unfixed>
486    

  ViewVC Help
Powered by ViewVC 1.1.5