/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7977 by nion, Sat Jan 19 14:02:27 2008 UTC revision 10248 by atomo64-guest, Sun Nov 2 23:52:15 2008 UTC
# Line 1  Line 1 
1  Embedded code copies  Embedded code copies
2  ====================  ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects which is considered bad for fixing security flaws  This is considered bad for fixing security flaws because the fix needs
6  because the fix needs to be applied in multiple source packages.  to be applied in multiple source packages.
7    
8  Format:  Format:
9  <srcpkg> (<optional comment about srcpkg>)  <srcpkg> (<optional comment about srcpkg>)
10          - <embedding srcpkg> <status> (<sort>; bug #<number>)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11          NOTE: optional comments about the linkage of the embedding srcpkg          NOTE: optional comments about the linkage of the embedding srcpkg
12    
13  status: version number fixing the embedded copy, <unfixed>, <removed>, <itp> or <unknown> if the version number can not be determined  status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp> or <unknown> if the version number can not be determined
15            <unfixable> for unavoidable cases (e.g., forks that add real value)
16  sort: static (linking statically against a lib)  sort: static (linking statically against a lib)
17        embed (embedding a copy of the library into another source package)        embed (embedding a copy of the library into another source package)
18        fork (the package is not just embedding code but it is a fork and thus might share parts of the source code)        fork (the package is not just embedding code but it is a fork and
19                thus might share parts of the source code)
20          old-version (the package is an older version of essentially
21                       the same code)
22    
23  The srcpkg might be some string to identify the code if there is no specific source package.  The srcpkg might be some string to identify the code if there is no
24    specific source package.
25    
26  Everything up to the next line is ignored  Everything up to the next line is ignored.
27  ---BEGIN  ---BEGIN
28  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29          NOTE: Fixed packages link to poppler library unless otherwise noted          NOTE: Fixed packages link to poppler library unless otherwise noted
# Line 30  xpdf (some srcpkgs use xpdf2 code, some Line 36  xpdf (some srcpkgs use xpdf2 code, some
36          NOTE: has been replaced by poppler-utils          NOTE: has been replaced by poppler-utils
37          - kdegraphics <unfixed> (embed; bug #436164)          - kdegraphics <unfixed> (embed; bug #436164)
38          NOTE: the kpdf replacement in KDE 4 is using poppler          NOTE: the kpdf replacement in KDE 4 is using poppler
39          - tetex-bin 3.0-12 (embed)          - texlive-base 3.0-12 (embed)
40          - texlive-bin 2007-1 (embed)          - texlive-bin 2007-1 (embed)
41          NOTE: links to poppler          NOTE: links to poppler
42          - koffice <unfixed> (embed; bug #436163)          - koffice <unfixed> (embed; bug #436163)
# Line 46  xpdf (some srcpkgs use xpdf2 code, some Line 52  xpdf (some srcpkgs use xpdf2 code, some
52  ppmd  ppmd
53          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55    peercast
56            - gnome-peercast <unfixed> (embed)
57            NOTE: gnome-peercast may better be removed, see #466539
58    
59  silc-toolkit  silc-toolkit
60          - silc-client 1.1~beta6-1 (embed)          - silc-client 1.1~beta6-1 (embed)
61    
# Line 142  pcre Line 152  pcre
152          - tf5 5.0beta7-1 (embed)          - tf5 5.0beta7-1 (embed)
153          - monotone <unfixed> (embed)          - monotone <unfixed> (embed)
154          NOTE: this only affects versions >= 0.37          NOTE: this only affects versions >= 0.37
155          - glib <unfixed> (embed)          - glib2.0 2.15.2-1 (embed)
         NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic  
156          - apache2 2.0.53-4 (embed)          - apache2 2.0.53-4 (embed)
157          - exim4 4.10-0.srh20.12 (embed)          - exim4 4.10-0.srh20.12 (embed)
158          - yacas <unfixed> (embed)          - yacas <unfixed> (embed)
159          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
160          - gtamsanalyzer.app 0.42-5 (embed)          - gtamsanalyzer.app 0.42-5 (embed)
161            - tin <unknown> (embed)
162            - kazehakase 0.5.2-1
163            - webkit <unfixed> (embed)
164            - qt4-x11 <unfixed> (embed)
165            NOTE: embedded via webkit copy
166    
167  tiff  tiff
168          - wxpythongtk <unfixed> (embed)          - wxwindows2.4 2.2.1 (embed)
         TODO: check, which debian pkg this is in  
169    
170  uudeview  uudeview
171          - libconvert-uulib-perl <unfixed> (embed)          - libconvert-uulib-perl <unfixed> (embed)
172            - pan <unfixed> (embed)
173    
174  sqlite (not affected by security vulnerabilities so far)  sqlite (not affected by security vulnerabilities so far)
175          - amarok <unfixed> (embed)          - amarok <unfixed> (embed)
# Line 185  chmlib Line 199  chmlib
199          - kchmviewer <unknown> (embed)          - kchmviewer <unknown> (embed)
200    
201  libavcodec/libavformat (source: ffmpeg)  libavcodec/libavformat (source: ffmpeg)
202          - mplayer <unfixed> (embed; bug #395252)          - mplayer 1.0~rc2-14 (embed; bug #395252)
203          - xvidcap <unfixed> (embed)          - kino 1.0.0-1
204          - kino <unfixed> (static)          - vlc <not-affected> (Links dynamically since initial release)
205          - vlc <unfixed> (static)          - smilutils 0.3.0-10
206          - smilutils <unfixed> (static)          NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
207          - motion <unfixed> (static)          - motion 3.1.19-1
208          - gst-ffmpeg <unfixed> (embed)          - gstreamer0.10-ffmpeg 0.10.3-2
         - gstreamer0.10-ffmpeg <unfixed> (embed)  
209          - xmovie <unfixed>          - xmovie <unfixed>
210          TODO: gimp-gap (potentially using ffmpeg code as well)          TODO: gimp-gap (potentially using ffmpeg code as well)
211    
# Line 225  uw-imap Line 238  uw-imap
238  imagemagick  imagemagick
239          - graphicsmagick <unfixed> (fork)          - graphicsmagick <unfixed> (fork)
240    
241    libphp-snoopy
242            - ampache <unfixed> (embed)
243            - mahara <unfixed> (embed)
244            - pixelpost <unfixed> (embed)
245    
246  halibut  halibut
247          - nsis <unfixed> (embed)          - nsis <unfixed> (embed)
248    
# Line 251  libmms Line 269  libmms
269          - mimms <unfixed> (embed)          - mimms <unfixed> (embed)
270    
271  fckeditor  fckeditor
272          - knowledgeroot <unfixed> (embed; bug #461555)          - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
273          - moin <unfixed> (embed; bug #452599)          - moin <unfixed> (embed; bug #452599)
274          - karrigell <unfixed> (embed; bug #452598)          - karrigell <removed> (embed; bug #452598)
275          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)
276    
277  ipatlas (not packaged in Debian)  ipatlas (not packaged in Debian)
# Line 261  ipatlas (not packaged in Debian) Line 279  ipatlas (not packaged in Debian)
279    
280  libphp-phpmailer  libphp-phpmailer
281          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
282            - mahara <unfixed> (embed)
283            - symfony <unfixed> (embed)
284            - phpgroupware-felamimail <unfixed> (embed)
285            NOTE: phpgroupware-felamimail is only in etch
286            - egroupware <unfixed> (embed; bug #504283)
287    
288  htmlArea (not packaged in Debian)  htmlArea (not packaged in Debian)
289          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
290    
291    giflib:
292            - wine <unfixed> (embed; bug #466181)
293    
294  bennu (not packaged in Debian)  bennu (not packaged in Debian)
295          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
296    
297  smarty:  smarty:
298          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #471158)
299            - gallery2 2.2.5-2 (embed; bug #471160)
300            - mahara 0.9.2-2 (embed; bug #471201)
301            - gosa 2.4beta1-1 (embed; bug #471200)
302    
303  TinyMCE  TinyMCE
304          - wordpress <unfixed> (embed)          - wordpress 2.5.1-3 (embed; bug #478257)
305          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
306          - knowledgeroot <unfixed> (embed)          - knowledgeroot <unfixed> (embed)
307          - joomla <itp> (bug #326398)          - joomla <itp> (bug #326398)
# Line 296  libphp-adodb Line 325  libphp-adodb
325          - cacti <unknown> (embed)          - cacti <unknown> (embed)
326          [sarge] - cacti <unfixed> (embed)          [sarge] - cacti <unfixed> (embed)
327          NOTE: dependency exists, but internal version is used          NOTE: dependency exists, but internal version is used
328            - gforge <unfixed> (embed)
329            - mahara <unfixed> (embed)
330    
331  gzip  gzip
332          - linux-kernel <unfixed> (embed)          - linux-kernel <unfixed> (embed)
# Line 343  libXaw Line 374  libXaw
374  libgd2  libgd2
375          - graphviz <unfixed> (embed)          - graphviz <unfixed> (embed)
376          NOTE: lib/gd seems to be 2.0.33          NOTE: lib/gd seems to be 2.0.33
377            - wml <unfixed> (embed)
378            NOTE: derived from gd 1.6.3
379    
380  rar  rar
381          - unrar-nonfree <unfixed> (embed)          - unrar-nonfree <unfixed> (embed)
# Line 364  fsplib (http://sourceforge.net/projects/ Line 397  fsplib (http://sourceforge.net/projects/
397          - gftp <unfixed> (embed)          - gftp <unfixed> (embed)
398          NOTE: lib/fsplib version 0.3          NOTE: lib/fsplib version 0.3
399    
400    sprng
401            - tree-puzzle <unfixed> (embed)
402    
403  librpcsecgss  librpcsecgss
404          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
405    
# Line 402  pax code Line 438  pax code
438  t1lib  t1lib
439          - tetex-bin 2.0.2-1 (embed)          - tetex-bin 2.0.2-1 (embed)
440          - texlive-bin <unknown> (embed)          - texlive-bin <unknown> (embed)
441    
442    guichan
443            - boswars <unfixed> (embed)
444            NOTE: maintainer notified us, working on it
445    
446    tolua
447            - boswars <unfixed> (embed)
448            NOTE: maintainer notified us, working on it
449    
450    asio-dev
451            - luxrender <unfixed> (embed)
452            NOTE: maintainer notified us, working on it
453            NOTE: may be merged with boost "soon"
454    
455    xine-lib
456            - vlc <unfixed> (embed)
457            NOTE: only parts included in modules/access/rtsp
458    
459    netpbm
460            - tcl8.3 <unfixed> (embed)
461            - tcl8.4 <unfixed> (embed)
462            - tcl8.5 <unfixed> (embed)
463            NOTE: generic/tkImgGIF.c
464    
465    tk8.5
466            - tk8.0 <removed> (old-version)
467            - tk8.3 <unfixed> (old-version)
468            - tk8.4 <unfixed> (old-version)
469            - perl-tk <unfixable> (fork)
470    
471    samba
472            - mc <unfixed> (embed)
473            NOTE: maintainer is aware of this, currently searching a solution
474    
475    plib1.8.4c2
476            - boson <unfixed> (fork)
477            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
478    
479    fribidi
480            - quesoglc <unfixed> (embed)
481    
482    glew
483            - quesoglc <unfixed> (embed)
484    
485    minorGems
486            - transcend <unfixed> (embed)
487            - cultivation <unfixed> (embed)
488    
489    tar
490            - libarchive <unfixed> (embed)
491            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
492    
493    cpio
494            - libarchive <unfixed> (embed)
495            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
496    
497    webkit
498            - qt4-x11 <unfixed> (embed)
499    
500    ftgl
501            - blender 2.46+dfsg-1 (embed)
502    
503    wv
504            - abiword <unfixed>
505    
506    qemu
507            - kvm <unfixed> (embed)
508            - xen-3 <unfixed> (embed)
509            - xen-unstable <unfixed> (embed)
510    
511    bochs
512            - kvm <unfixed> (embed; bug #489442)
513    
514    speex
515            - vorbis-tools <unfixed> (embed)
516            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
517            - gst-plugins-good0.10 <unfixed> (embed)
518            - xine-lib <unfixed> (embed)
519            - libfishsound <unfixed> (embed)
520            - libannodex <unfixed> (embed)
521            - vlc <unfixed> (embed)
522            - xmms-speex <unfixed> (embed)
523            - libsdl-sound1.2 <unfixed> (embed)
524            - sweep <unfixed> (embed)
525    
526    libreadline
527            - magic <unfixed> (old-version)
528            NOTE: magic is currently an RFS
529    
530    opcode
531            - ode <unfixed> (embed)
532            NOTE: opcode is not a package in debian, it is just embedded
533            NOTE: http://www.codercorner.com/Opcode.htm
534    
535    gimpact
536            - ode <unfixed> (embed)
537            NOTE: gimpact is not a package in debian, it is just embedded
538            NOTE: http://gimpact.sf.net
539    
540    mochikit
541            - mahara <unfixed> (embed)
542            NOTE: they require extra patches, still unmerged upstream
543            - ntop <unfixed> (embed)
544            - python-oherence <unfixed> (embed)
545            - python-paste <unfixed> (embed)
546            - python-turbogears <unfixed> (embed)
547            - zope-plone3 <unfixed> (embed)
548    
549    prototype
550            - netbeans-ide <unfixed> (embed)
551            - auth2db-frontend <unfixed> (embed)
552            - citadel-webcit <unfixed> (embed)
553            - asterisk <unfixed> (embed)
554            - doc-iana <unfixed> (embed)
555            - libaws-doc <unfixed> (embed)
556            - libgettext-ruby-data <unfixed> (embed)
557            - libjson-ruby-doc <unfixed> (embed)
558            - liblucene2-java-doc <unfixed> (embed)
559            - libopenid-ruby <unfixed> (embed)
560            - solr-common <unfixed> (embed)
561            - glpi <unfixed> (embed)
562            - hobbix <unfixed> (embed)
563            - mnemo2 <unfixed> (embed)
564            - nag2 <unfixed> (embed)
565            - knowledgeroot <unfixed> (embed)
566            - mediatomb-common <unfixed> (embed)
567            - mt-daapd <unfixed> (embed)
568            - op-panel <unfixed> (embed)
569            - ebug-http <unfixed> (embed)
570            - phpgedview <removed> (embed)
571            - poker-web <unfixed> (embed)
572            - python-webhelpers <unfixed> (embed)
573            - qwik <unfixed> (embed)
574            - rails <unfixed> (embed)
575            - typo3-src-4.1 <unfixed> (embed)
576            - wordpress <unfixed> (embed)
577            - zope-plone3 <unfixed> (embed)
578            - smokeping <unfixed> (embed)
579            - ampache 3.4.1-2 (embed)
580            - exaile <unfixed> (embed)
581            - hobix <unfixed> (embed)
582            - pixelpost <unfixed> (embed)
583            - symfony <unfixed> (embed)
584            NOTE: it's been said that there are custom changes
585            - zabbix-frontend-php <unfixed> (embed)
586            - turba2 <unfixed> (embed)
587    
588    gdb
589            - insight <unfixed> (embed)
590    
591    e2fsprogs
592            - ldiskfsprogs <unfixable> (fork)
593    
594    quazip (not packaged in Debian)
595            - qcake <unfixed> (embed)
596            NOTE: starting with upstream version 0.6.4
597    
598    exo
599            - pcmanfm <unfixed> (embed; bug #499677)
600            NOTE: slightly modified source code
601    
602    java
603            - openjdk-6 <unfixed>
604            - sun-java5 <unfixed>
605            - sun-java6 <unfixed>
606    
607    libphp-snoopy
608            - ampache 3.4.1-2 (embed; bug #504169)
609            - mahara <unfixed> (embed; bug #504170)
610            - pixelpost <unfixed> (embed; bug #504171)
611            - mediamate 0.9.3.6-5 (embed; bug #504172)
612            - opendb <unfixed> (embed; bug #504173)
613            - wordpress <unfixed> (embed; bug #443948)
614            - moodle <unfixed> (embed)
615            - phpgroupware-felamimail <unfixed> (embed)
616            NOTE: phpgroupware-felamimail is only in etch
617            - magpierss 0.72-3 (embed; bug #431089)
618    
619    jquery
620            - zekr <unfixed> (embed)
621            - wordpress <unfixed> (embed)
622            - yocto-reader <unfixed> (embed)
623            - textpattern <unfixed> (embed)
624            - genshi <unfixed> (embed)
625            NOTE: compressed file under examples/ dir
626            - prewikka <unfixed> (embed)
627            - libramaze-ruby <unfixed> (embed)
628            - drupal5 <unfixed> (embed)
629            - b2evolution <unfixed> (embed)
630    
631    kses
632            - wordpress <unfixed> (embed; bug #504242)
633            NOTE: their copy has all methods renamed to wp_<foo>
634            - moodle <unfixed> (embed)
635            - egroupware-core <unfixed> (embed)
636    
637    magpierss
638            - wordpress <unfixed> (embed; bug #504242)
639    
640    php-gettext
641            - wordpress <unfixed> (embed; bug #504242)
642    
643    libphp-ixr (name may change, it is the Incutio XML-RPC)
644            - wordpress <unfixed> (embed; bug #504242)
645            - dokuwiki <unfixed> (embed)
646            - textpattern <unfixed> (embed)
647    
648    domxml-php4-to-php5.php
649            - glpi <unfixed> (embed)
650            - moodle <unfixed> (embed; bug #496069)
651    
652    scriptaculous
653            - glpi <unfixed> (embed)
654            - libaws-doc <unfixed> (embed)
655            - op-panel <unfixed> (embed)
656            - symfony <unfixed> (embed)
657            NOTE: maintainer says there are extra incompatible changes required
658            - pixelpost <unfixed> (embed)
659            - python-webhelpers <unfixed> (embed)
660            - qwik <unfixed> (embed)
661            - smokeping <unfixed> (embed)
662            - turba2 <unfixed> (embed)
663            - typo3-src <unfixed> (embed)
664    
665    libmarkdown-php
666            - moodle <unfixed> (embed)
667            - pixelpost <unfixed> (embed)
668    
669    php-openid
670            - wordpress-openid <itp> (embed)

Legend:
Removed from v.7977  
changed lines
  Added in v.10248

  ViewVC Help
Powered by ViewVC 1.1.5