/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7841 by nion, Sun Jan 6 16:13:03 2008 UTC revision 13435 by pabs, Thu Dec 3 09:40:23 2009 UTC
# Line 1  Line 1 
1  Embedded code copies  Embedded code copies
2  ====================  ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects which is considered bad for fixing security flaws  This is considered bad for fixing security flaws because the fix needs
6  because the fix needs to be applied in multiple source packages.  to be applied in multiple source packages.
7    
8  Format:  Format:
9  <srcpkg> (<optional comment about srcpkg>)  <srcpkg> (<optional comment about srcpkg>)
10          - <embedding srcpkg> <status> (<sort>; bug #<number>)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11          NOTE: optional comments about the linkage of the embedding srcpkg          NOTE: optional comments about the linkage of the embedding srcpkg
12    
13  status: version number fixing the embedded copy, <unfixed>, <removed>, <itp> or <unknown> if the version number can not be determined  status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp>, <not-affected>, <unknown> if the version number can not
15            be determined, or <unfixable> for unavoidable cases (e.g., forks
16            that add real value)
17  sort: static (linking statically against a lib)  sort: static (linking statically against a lib)
18        embed (embedding a copy of the library into another source package)        embed (embedding a copy of the library into another source package)
19        fork (the package is not just embedding code but it is a fork and thus might share parts of the source code)        fork (the package is not just embedding code but it is a fork and
20                thus might share parts of the source code)
21          old-version (the package is an older version of essentially
22                       the same code)
23    
24  The srcpkg might be some string to identify the code if there is no specific source package.  The srcpkg might be some string to identify the code if there is no
25    specific source package.
26    
27    Everything up to the next line is ignored.
28    ---BEGIN
29  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
30          NOTE: Fixed packages link to poppler library unless otherwise noted          NOTE: Fixed packages link to poppler library unless otherwise noted
         - gpdf <removed>  
         [sarge] - gpdf <unfixed>  
         NOTE: has been replaced by evince in etch  
31          - pdftohtml <unknown>          - pdftohtml <unknown>
32          [sarge] - pdftohtml <unfixed>          [sarge] - pdftohtml <unfixed>
33          [etch] - pdftohtml <unfixed>          [etch] - pdftohtml <unfixed>
34          NOTE: has been replaced by poppler-utils          NOTE: has been replaced by poppler-utils
35          - kdegraphics <unfixed> (embed; bug #436164)          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
36          NOTE: the kpdf replacement in KDE 4 is using poppler          - texlive-base 3.0-12 (embed)
         - tetex-bin 3.0-12 (embed)  
37          - texlive-bin 2007-1 (embed)          - texlive-bin 2007-1 (embed)
38          NOTE: links to poppler          NOTE: links to poppler
39          - koffice <unfixed> (embed; bug #436163)          - koffice <unfixed> (embed; bug #436163)
40          - libextractor 0.5.12-1 (embed)          - libextractor 0.5.12-1 (embed)
41          NOTE: libextractor is using its own pdf decoder now          NOTE: libextractor is using its own pdf decoder now
         - libextractor 0.5.12-1 (embed)  
         - pdfkit.framework 0.8-4 (embed)  
42          - ipe <unfixed> (embed)          - ipe <unfixed> (embed)
43          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44          - ruby-gnome2 <unknown> (embed)          - ruby-gnome2 <unknown> (embed)
45          NOTE: copy only present in source but links to poppler          NOTE: copy only present in source but links to poppler
46            - pdfedit <unfixed> (embed; bug #510794)
47            - swftools <unfixed> (embed; bug #551293)
48            - poppler <unfixable> (fork)
49    
50  ppmd  ppmd
51          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)          - libcomplearn-mod-ppmd <unfixed> (fork)
52            NOTE: discussion in #458152
53    
54    libevent
55            - transmission 1.71-1 (embed; bug #529372)
56    
57    lrmi
58            - read-edid 2.0.0-1 (embed; bug #495131)
59    
60    peercast
61            - gnome-peercast <removed> (embed)
62            [etch] - gnome-peercast <unfixed> (embed)
63    
64  silc-toolkit  silc-toolkit
65          - silc-client 1.1~beta6-1 (embed)          - silc-client 1.1~beta6-1 (embed)
66    
67    icclib
68            - ghostscript <unfixed> (embed)
69            - argyll <unfixed> (embed)
70    
71  dietlibc  dietlibc
72          - ccontrol 0.9.1+20071204-1 (static)          - ccontrol 0.9.1+20071204-1 (static)
73    
74    libmikmod
75            - sdl-mixer1.2 <unfixed> (embed)
76            TODO: report bug
77    
78  libiax  libiax
79          - iaxmodem <unfixed> (embed)          - iaxmodem <unfixable> (embed; bug #548885)
80    
81    spandsp
82            - iaxmodem <unfixable> (embed; bug #548885)
83    
84  zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
85          - dpkg <unfixed> (embed)          - dpkg <unfixed> (embed)
# Line 65  zlib (lots of apps embed a copy, but lin Line 93  zlib (lots of apps embed a copy, but lin
93          - mrtg 2.12.2-1 (embed)          - mrtg 2.12.2-1 (embed)
94          - rpm <unknown> (embed)          - rpm <unknown> (embed)
95          NOTE: pinged anibal since when rpm was fixed          NOTE: pinged anibal since when rpm was fixed
96            - tuxcmd-modules <unfixed> (embed)
97            - zsync <unfixed>
98            - tra <unfixed>
99            - sash <unfixed>
100            - nsis <unfixed>
101            - mseide-msegui <unfixed>
102            NOTE: mseide
103            - mirrordir <unfixed>
104            - poco <unfixed>
105            - klibc <unfixed>
106            - ghostscript <unfixed>
107            - freeimage <unfixed>
108            - clamav <unfixed> (fork)
109            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
110            - tuxonice-userui <unfixed>
111            - plt-scheme <unfixed>
112            - perl <unfixed>
113            - paraview <unfixed>
114            - gcvs <unfixed>
115            - dump <unfixed>
116            - aide <unfixed> (static)
117            - dar <unfixed> (static)
118            - avfs <unfixed>
119            - fpc <unfixed>
120            - winff <unfixed>
121            NOTE: inherited from fpc, see #472304
122            - lazarus <unfixed>
123            NOTE: inherited from fpc, see #472304
124            - erlang <unfixed> (embed)
125            - gamera 3.2.3-1 (embed)
126            - python2.4 <unfixed> (embed; bug #553403)
127            - python2.5 <unfixed> (embed; bug #553403)
128    
129    dulwich
130            - hg-git 0.1.0-1 (embed; bug #541996)
131    
132    libvigraimpex
133            - hugin <unfixed> (embed; bug #542259)
134            - enblend-enfuse <unfixed> (embed; bug #542258)
135            - gamera 3.2.3-1 (embed)
136    
137  libbz2  libbz2
138          - dpkg <unfixed> (static)          - dpkg <unfixed> (static)
139    
140  ekg  libgadu
141          - centericq <unfixed> (embed)          - centericq <unfixed> (embed)
142          - gaim <unfixed> (embed)          - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
143          - pigdin <unfixed> (embed)(links dynamically against libgadu)          - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
144          - kopete 4:3.3.2-5 (embed)          - kdenetwork 4:3.3.2-5 (embed)
145          - kadu <unfixed> (embed)          NOTE: from kdenetwork: kopete
146          - gadu <unfixed> (embed)          - ekg 1:1.8~rc0-1 (embed)
147          NOTE: g/kadu not packaged in Debian yet          - kadu 0.6.0.2-3 (embed; bug #504430)
148            - gadu <itp> (embed)
149    
150  xmlrpc (which package is the "origin" of this code?)  xmlrpc (which package is the "origin" of this code?)
151          - drupal <unfixed> (embed)          - drupal <unfixed> (embed)
152          - phpgroupware <unfixed> (embed)          - phpgroupware <unfixed> (embed)
153          - egroupware <unfixed> (embed)          - egroupware <unfixed> (embed)
154          - phpwiki (embed)          - phpwiki <unfixed> (embed)
155          - php4 <unfixed> (embed)          - php4 <unfixed> (embed)
156          TODO: check, php-pear, IIRC this was reorganized some weeks ago?          TODO: check, php-pear, IIRC this was reorganized some weeks ago?
157    
# Line 90  shtool (affects build-time only) Line 159  shtool (affects build-time only)
159          - mysql-ocaml <unfixed> (embed)          - mysql-ocaml <unfixed> (embed)
160          - php4 <unfixed> (embed)          - php4 <unfixed> (embed)
161    
162  mozilla source code  iceape
163          - mozilla-firefox <unfixed> (embed)          - iceweasel <unfixed> (fork)
164          - mozilla-thunderbird          - icedove <unfixed> (fork)
165          - firefox <removed>          - xulrunner <unfixed> (fork)
166          [etch] - firefox <unfixed> (embed)          - kompozer <unfixed> (embed; bug #532168)
167          - thunderbird <removed>          - galeon <unfixed> (fork)
168          [etch] - thunderbird <unfixed> (embed)          - epiphany-browser <unfixed> (fork)
169          - iceweasel <unfixed> (embed)          - conkeror <unfixed> (fork)
170          - iceape <unfixed> (embed)          - kazehakase <unfixed> (fork)
         - icedove <unfixed> (embed)  
         - xulrunner <unfixed> (embed)  
         - nvu <removed> (embed)  
171    
172  xli  xli
173          - xloadimage <unfixed> (embed)          - xloadimage <unfixed> (embed)
174    
175  lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
176          - openmotif <unfixed> (embed)          - openmotif <unfixed> (embed)
177          - xfree86/xorg <unfixed> (embed)          - libxpm <unfixed> (embed)
         NOTE: in libxpm  
178    
179  kerberized apps with BSD origin  kerberized apps with BSD origin
180          - krb4 <unfixed> (embed)          - krb4 <removed> (embed)
181          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
182          - heimdal <unfixed> (embed)          - heimdal <unfixed> (embed)
183    
184  grip (which pkg is the origin?)  grip (which pkg is the origin?)
185          - libcdaudio          - libcdaudio <unfixed>
186          - grip          - grip <unfixed>
187          - gnome-vfs          - gnome-vfs <unfixed>
188          TODO: check vfs2 as well          TODO: check vfs2 as well
189    
190  fudforum  fudforum
191          - phpgroupware-fudforum <unfixed> (embed)          [etch] - phpgroupware <unfixed> (embed)
192          - egroupware-fudforum <removed>          NOTE: phpgroupware-fudforum
193          [sarge] - egroupware-fudforum <unfixed> (embed)          [sarge] - egroupware-fudforum <removed> (embed)
194    
195    libbsd
196            - rdate 1:1.2-3 (embed)
197            - atheme-services <unfixed>
198            - libbsd-arc4random-perl <unfixed>
199            - isakmpd <unfixed>
200    
201  cvs  cvs
202          - gcvs <unfixed> (embed)          - gcvs <unfixed> (embed)
203          NOTE: see cvsunix/src in tarball          NOTE: see cvsunix/src in tarball
204    
205  pcre  pcre3
         - python* <unfixed> (embed)  
206          - php4 <unknown> (embed)          - php4 <unknown> (embed)
207          - analog 2:5.23-0woody1 (embed)          - analog 2:5.23-0woody1 (embed)
208          - libgoffice-1 <unfixed> (embed)          - goffice <unfixed> (embed)
209            NOTE: libgoffice-*
210          - vfu 4.06-4.1 (embed; bug #450754)          - vfu 4.06-4.1 (embed; bug #450754)
211          - tf5 5.0beta7-1 (embed)          - tf5 5.0beta7-1 (embed)
212          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
213          NOTE: this only affects versions >= 0.37          NOTE: this only affects versions >= 0.37
214          - glib <unfixed> (embed)          - glib2.0 2.15.2-1 (embed)
         NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic  
215          - apache2 2.0.53-4 (embed)          - apache2 2.0.53-4 (embed)
216          - exim4 4.10-0.srh20.12 (embed)          - exim4 4.10-0.srh20.12 (embed)
217          - yacas <unfixed> (embed)          - yacas <unfixed> (embed)
218          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
219          - gtamsanalyzer.app 0.42-5 (embed)          - gtamsanalyzer.app 0.42-5 (embed)
220            - tin 980117-1 (embed)
221            - kazehakase 0.5.2-1
222            - webkit 1.0.1-1 (embed)
223            - qt4-x11 <unfixed> (embed)
224            NOTE: embedded via webkit copy
225            - erlang <unfixed> (embed)
226    
227  tiff  tiff
228          - wxpythongtk <unfixed> (embed)          - wxwindows2.4 2.2.1 (embed)
229          TODO: check, which debian pkg this is in          - gamera 3.2.3-1 (embed)
230    
231  uudeview  uudeview
232          - libconvert-uulib-perl <unfixed> (embed)          - libconvert-uulib-perl <unfixed> (embed)
233            - pan <unfixed> (embed)
234    
235  sqlite (not affected by security vulnerabilities so far)  sqlite (not affected by security vulnerabilities so far)
236          - amarok <unfixed> (embed)          - amarok <unfixed> (embed)
237          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
238          - iceweasel <unfixed> (embed)          - iceweasel <unfixed> (embed)
239    
240  util-linux/mount  util-linux/mount
241          - loop-aes-utils <unfixed> (embed)          - loop-aes-utils <unfixed> (embed)
242          NOTE: contains code from util-linux' mount in the mount-aes-udeb          NOTE: contains code from util-linux' mount in the mount-aes-udeb
243    
 webmin  
         - usermin <unknown> (embed)  
         [sarge] - usermin <unfixed> (embed)  
   
244  sylpheed  sylpheed
245          - sylpheed-claws <unfixed> (fork)          - sylpheed-claws <unfixed> (fork)
246    
# Line 176  phpsysinfo Line 249  phpsysinfo
249          - phpgroupware <unfixed> (embed)          - phpgroupware <unfixed> (embed)
250    
251  phpldapadmin  phpldapadmin
252          - [sarge] egroupware <unfixed> (embed)          [sarge] - egroupware <unfixed> (embed)
253          NOTE: removed from egroupware after sarge          NOTE: removed from egroupware after sarge
254    
255  chmlib  chmlib
256          - kchmviewer <unknown> (embed)          - kchmviewer <unknown> (embed)
257    
258  libavcodec/libavformat (source: ffmpeg)  ffmpeg (libavcodec/libavformat)
259          - mplayer <unfixed> (embed; bug #395252)          - mplayer 1.0~rc2-14 (embed; bug #395252)
260          - xvidcap <unfixed> (embed)          - kino 1.0.0-1
261          - kino <unfixed> (static)          - vlc <not-affected> (Links dynamically since initial release)
262          - vlc <unfixed> (static)          - smilutils 0.3.0-10
263          - smilutils <unfixed> (static)          NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
264          - motion <unfixed> (static)          - motion 3.1.19-1
265          - gst-ffmpeg <unfixed> (embed)          - gstreamer0.10-ffmpeg 0.10.3-2
266          - gstreamer0.10-ffmpeg <unfixed> (embed)          - xmovie <removed> (static)
         - xmovie <unfixed>  
267          TODO: gimp-gap (potentially using ffmpeg code as well)          TODO: gimp-gap (potentially using ffmpeg code as well)
268            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
269    
270    faad2
271            - mplayer 1.0~rc2-20 (embed)
272            - avifile <unfixed> (embed; bug #538750)
273            - ffmpeg-debian <removed> (old-version)
274    
275  mad MPEG decoding lib  libmad (MPEG decoding lib)
         - mad <unfixed> (embed)  
276          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
277            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
278            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
279    
280  libdts  libdts
281          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
# Line 212  libmpeg2 Line 291  libmpeg2
291          - mpeg2dec <unfixed> (embed)          - mpeg2dec <unfixed> (embed)
292          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
293    
294  curl  libntlm
295          - wget <unfixed> (embed)          - wget <unfixed> (fork; bug #550436)
296          NOTE: code for NTLM authentication          - curl <unfixed> (fork; bug #550437)
297            - cntlm <unfixed> (fork; bug #550438)
298    
299  uw-imap  uw-imap
300          - pine <unfixed> (embed)          - pine <unfixed> (embed)
# Line 223  uw-imap Line 303  uw-imap
303  imagemagick  imagemagick
304          - graphicsmagick <unfixed> (fork)          - graphicsmagick <unfixed> (fork)
305    
306    python-urlgrabber
307            - mercurial <unfixed> (embed; bug #531062)
308            - w3af <unfixed> (embed; bug #555372)
309            [experimental] - harvestman <unfixed> (embed; bug #555373)
310    
311    beautifulsoup
312            - python-mechanize <unfixed> (embed; bug #555349)
313            - zope2.11 <unfixed> (embed; bug #555350)
314            - twill <unknown> (embed)
315    
316  halibut  halibut
317          - nsis <unfixed> (embed)          - nsis <unfixed> (fork)
318    
319  libghttp  libghttp
320          - hotway <unfixed> (embed)          - hotway <unfixed> (embed)
321    
322  libsndfile  libsndfile
323          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
324    
325  glibmm2.4  glibmm2.4
326          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
327    
328  libgnomecanvasmm2.6  libgnomecanvasmm2.6
329          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
330    
331  libsigc++-2.0  libsigc++-2.0
332          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
333    
334  soundtouch  soundtouch
335          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
336    
337  libmms  libmms
338          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
339          - mimms <unfixed> (embed)          - mimms <unfixed> (embed)
340    
341  fckeditor  fckeditor
342          - knowledgeroot <unfixed> (embed)          - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
343          - moin <unfixed> (embed; bug #452599)          - moin 1.8.2-2 (embed; bug #452599)
344          - karrigell <unfixed> (embed; bug #452598)          - karrigell <removed> (embed; bug #452598)
345          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)          - gforge 4.6.99+svn6225-1 (embed)
346            - request-tracker3.8 <unfixed> (embed)
 libphp-adodb  
         - moodle <unfixed> (embed)  
         NOTE: also AdoDB-XML Schema  
347    
348  ipatlas (not packaged in Debian)  ipatlas (not packaged in Debian)
349          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
350    
351  libphp-phpmailer  libphp-phpmailer
352          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
353            - mahara <unfixed> (embed)
354            - symfony <unfixed> (embed)
355            [etch] - phpgroupware <unfixed> (embed)
356            NOTE: phpgroupware-felamimail is only in etch
357            - egroupware <unfixed> (embed; bug #504283)
358            - glpi <unfixed>
359    
360  htmlArea (not packaged in Debian)  htmlArea (not packaged in Debian)
361          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
362    
363  bennu (not packaged in Debian)  giflib
364          - moodle <unfixed> (embed)          - wine <unfixed> (embed; bug #466181)
365    
366  smarty:  bennu (not packaged in Debian, http://bennu.sourceforge.net)
367          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
368    
369    smarty
370            - moodle 1.8.2-2 (embed; bug #471158)
371            - gallery2 2.2.5-2 (embed; bug #471160)
372            - mahara 0.9.2-2 (embed; bug #471201)
373            - gosa 2.4beta1-1 (embed; bug #471200)
374    
375  TinyMCE  TinyMCE
376          - wordpress <unfixed> (embed)          - wordpress 2.5.1-3 (embed; bug #478257)
377          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
378          - knowledgeroot <unfixed> (embed)          - knowledgeroot <unfixed> (embed)
379          - joomla <itp> (bug #326398)          - joomla <itp> (bug #326398)
380    
381  scintilla  scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
382          - scite <unfixed> (embed)          - scite <unfixed> (embed)
383          - qscintilla <unfixed> (embed)          - qscintilla <unfixed> (embed)
384          - qscintilla2 <unfixed> (embed)          - qscintilla2 <unfixed> (embed)
385          - geany <unfixed> (embed)          - geany <unfixed> (fork)
386            - anjuta <unfixed> (embed)
387    
388  libphp-adodb  libphp-adodb
389            - moodle <unfixed> (embed; bug #507185)
390            NOTE: also AdoDB-XML Schema
391          - gallery2 <unfixed> (embed)          - gallery2 <unfixed> (embed)
392          - phppgadmin <unfixed> (embed)          - phppgadmin <unfixed> (embed)
393          - egroupware <unfixed> (embed)          - egroupware <unfixed> (embed)
394          - phpwiki <unfixed> (embed)          - phpwiki <unfixed> (embed)
395            - torrentflux 2.0beta1-2 (embed)
396          - ipplan <unfixed> (embed)          - ipplan <unfixed> (embed)
397          - typo3 <unfixed> (embed)          - typo3-src <unfixed> (embed)
         - moodle <unfixed> (embed)  
398          - cacti <unknown> (embed)          - cacti <unknown> (embed)
399          [sarge] - cacti <unfixed> (embed)          [sarge] - cacti <unfixed> (embed)
400          NOTE: dependency exists, but internal version is used          NOTE: dependency exists, but internal version is used
401            - gforge 4.7~rc2-6 (embed)
402            - mahara <unfixed> (embed)
403    
404  gzip  gzip
405          - linux-kernel <unfixed> (embed)          - linux-kernel <unfixed> (embed)
# Line 305  gzip Line 409  gzip
409          - busybox <unfixed> (embed)          - busybox <unfixed> (embed)
410    
411  neon  neon
412          - cadaver <unfixed> (embed; bug #188381)          - cadaver 0.22.3+debian-1 (embed; bug #188381)
413          - gnome-vfs2 <unfixed> (embed; bug #395874)          - gnome-vfs2 <unfixed> (embed; bug #395874)
414          - litmus <unfixed> (embed; #395875)          [etch] - litmus <unfixed> (embed; #395875)
415            - litmus <removed> (embed; #395875)
416          [sarge] - screem <unfixed> (embed)          [sarge] - screem <unfixed> (embed)
417          - sitecopy <unfixed> (embed; bug #395876)          - sitecopy 1:0.16.3-5 (embed; bug #395876)
418          - [etch] tla <unfixed> (embed; bug #395877)          [etch] - tla <unfixed> (embed; bug #395877)
419          - [sarge] tla <unfixed> (embed; bug #395877)          [sarge] - tla <unfixed> (embed; bug #395877)
420    
421  libmodplug  libmodplug
422          - gst-plugins-bad0.10 <unfixed> (embed)          - gst-plugins-bad0.10 <unfixed> (embed)
# Line 328  tinyxml (not packaged in Debian) Line 433  tinyxml (not packaged in Debian)
433  gv  gv
434          - evince <unfixed> (embed)          - evince <unfixed> (embed)
435          NOTE: ps/ tree from gv 3.5.8          NOTE: ps/ tree from gv 3.5.8
436          - evince-gtk <unfixed> (embed)          NOTE: evince-gtk is affected (a component of evince source package)
         NOTE: not packaged in Debian  
437    
438  libXbae  libXbae
439          [etch] - libpawlib2-lesstif <unfixed> (embed)          - paw <removed> (embed)
440          NOTE: from Cernlib          [etch] - paw <unfixed> (embed)
441    
442    libgtkhtml
443            - claws-mail-extra-plugins <unfixed> (fork)
444    
445  libXaw  libXaw
446          [etc] - libpawlib2-lesstif          - paw <removed> (embed)
447          NOTE: from Cernlib          [etch] - paw <unfixed> (embed)
448          NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty          NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
449    
450  libgd2  libgd2
451          - graphviz <unfixed> (embed)          - graphviz <unfixed> (embed)
452          NOTE: lib/gd seems to be 2.0.33          NOTE: lib/gd seems to be 2.0.33
453            - wml <unfixed> (embed)
454            - libwmf <unfixed> (embed)
455            NOTE: derived from gd 1.6.3
456    
457  rar  rar
458          - unrar-nonfree <unfixed> (embed)          - unrar-nonfree <unfixed> (embed)
# Line 356  mplayer (DirectMedia Object loader) Line 466  mplayer (DirectMedia Object loader)
466          NOTE: src/libw32dll/          NOTE: src/libw32dll/
467          - vlc <unfixed> (embed)          - vlc <unfixed> (embed)
468          NOTE: modules/codec/dmo/          NOTE: modules/codec/dmo/
469            - mplayer 1.0~rc2-20 (embed)
470    
471  libwpd (WordPerfect converter)  libwpd (WordPerfect converter)
472          - openoffice.org <unfixed> (embed)          - openoffice.org <unfixed> (embed)
# Line 364  fsplib (http://sourceforge.net/projects/ Line 475  fsplib (http://sourceforge.net/projects/
475          - gftp <unfixed> (embed)          - gftp <unfixed> (embed)
476          NOTE: lib/fsplib version 0.3          NOTE: lib/fsplib version 0.3
477    
478    sprng
479            - tree-puzzle <unfixed> (embed)
480    
481  librpcsecgss  librpcsecgss
482          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
483    
# Line 371  jasper Line 485  jasper
485          - ghostscript <unfixed> (embed)          - ghostscript <unfixed> (embed)
486          - gs-gpl <unfixed> (embed)          - gs-gpl <unfixed> (embed)
487    
488    libiris
489            - psi <unfixed> (embed)
490            - kdenetwork <unfixed> (embed)
491            NOTE: kopete embeds libiris but links dynamically to libidn
492            - kdegames <unfixed> (embed)
493            NOTE: ksirk/kde4
494    
495  libidn  libidn
496          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
497            - psi <unfixed> (embed)
498            NOTE: psi embeds libiris which embeds libidn
499            - kdegames <unfixed> (embed)
500            NOTE: kdegames/kde4 embeds libiris which embeds libidn
501    
502  liblua  liblua
503          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
504            - nmap 5.00-1 (embed; bug #527997)
505            [lenny] - nmap <unfixed> (embed; bug #527997)
506            - ocropus <unfixed> (embed)
507    
508  libbotan  libbotan
509          - montone <unfixed> (embed)          - monotone 0.43-1 (embed)
510    
511  NetXX  NetXX
512          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
513    
514  libgc  libgc
515          - mono <unfixed> (embed)          - mono <unfixed> (embed)
516    
517  lzma  lzma
518          - p7zip <unfixed> (embed)          - p7zip <unfixed> (embed)
519            - xz-utils <unfixed> (fork)
520    
521  lzo  lzo
522          - grub2 <unfixed> (embed)          - grub2 <unfixed> (embed)
523    
524    yassl
525            - mysql-dfsg-5.0 <unfixed> (embed)
526    
527  pax code  pax code
528          - tar <unfixed> (embed)          - tar <unfixed> (embed)
529          - cpio <unfixed> (embed)          - cpio <unfixed> (embed)
# Line 399  pax code Line 531  pax code
531  t1lib  t1lib
532          - tetex-bin 2.0.2-1 (embed)          - tetex-bin 2.0.2-1 (embed)
533          - texlive-bin <unknown> (embed)          - texlive-bin <unknown> (embed)
534    
535    guichan
536            - boswars <unfixed> (embed)
537            NOTE: maintainer notified us, working on it
538    
539    tolua
540            - boswars <unfixed> (embed)
541            NOTE: maintainer notified us, working on it
542            - ocropus <unfixed> (embed)
543            - freeciv <unfixed> (embed)
544    
545    asio-dev
546            - luxrender <removed> (embed)
547    
548    xine-lib
549            - vlc <unfixed> (embed)
550            NOTE: only parts included in modules/access/rtsp
551    
552    netpbm
553            - tcl8.3 <unfixed> (embed)
554            - tcl8.4 <unfixed> (embed)
555            - tcl8.5 <unfixed> (embed)
556            NOTE: generic/tkImgGIF.c
557    
558    tk8.5
559            - tk8.0 <removed> (old-version)
560            - tk8.3 <unfixed> (old-version)
561            - tk8.4 <unfixed> (old-version)
562            - perl-tk <unfixable> (fork)
563    
564    samba
565            - mc 2:4.6.2~git20080311-1 (embed)
566            NOTE: maintainer is aware of this, currently searching a solution
567    
568    plib1.8.4c2
569            - boson <unfixed> (fork)
570            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
571    
572    fribidi
573            - quesoglc <unfixed> (embed)
574            NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
575    
576    glew
577            - quesoglc <unfixed> (embed; bug #489341)
578            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
579            - trigger <unfixed> (embed)
580            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
581            - trigger-rally <unfixed> (embed)
582            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
583    
584    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
585            - transcend <unfixed> (embed)
586            - cultivation <unfixed> (embed)
587            - passage <unfixed> (embed)
588            - gravitation <unfixed> (embed)
589    
590    tar
591            - libarchive <unfixed> (embed)
592            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
593    
594    cpio
595            - libarchive <unfixed> (embed)
596            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
597    
598    webkit
599            - qt4-x11 <unfixed> (embed)
600    
601    ftgl
602            - blender 2.46+dfsg-1 (embed)
603    
604    wv
605            - abiword <unfixed>
606    
607    qemu
608            - kvm <unfixed> (embed; bug #543159)
609            - xen-3 <unfixed> (embed)
610            - xen-unstable <unfixed> (embed)
611    
612    vgabios
613            - kvm <unfixed> (embed; bug #489442)
614    
615    bochs
616            - kvm <unfixed> (embed; bug #489442)
617    
618    speex
619            - vorbis-tools <unfixed> (embed)
620            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
621            - gst-plugins-good0.10 <unfixed> (embed)
622            - xine-lib <unfixed> (embed)
623            - libfishsound <unfixed> (embed)
624            - libannodex <unfixed> (embed)
625            - vlc <unfixed> (embed)
626            - xmms-speex <unfixed> (embed)
627            - libsdl-sound1.2 <unfixed> (embed)
628            - sweep <unfixed> (embed)
629    
630    libreadline
631            - magic <itp> (old-version)
632    
633    opcode
634            - ode <unfixed> (embed)
635            NOTE: opcode is not a package in debian, it is just embedded
636            NOTE: http://www.codercorner.com/Opcode.htm
637    
638    gimpact
639            - ode <unfixed> (embed)
640            NOTE: gimpact is not a package in debian, it is just embedded
641            NOTE: http://gimpact.sf.net
642    
643    mochikit
644            - mahara <unfixed> (embed)
645            NOTE: they require extra patches, still unmerged upstream
646            - ntop <unfixed> (embed)
647            - coherence 0.6.2-1 (embed)
648            - paste <unfixed> (embed)
649            - turbogears <unfixed> (embed)
650            - plone3 <unfixed> (embed)
651            - xulrunner <unfixed> (embed)
652            - libjifty-plugin-chart-perl <unfixed> (embed)
653            - sabnzbdplus <unfixed> (embed)
654            - tgmochikit <unfixed> (embed)
655    
656    prototypejs
657            - netbeans-ide 6.0.1+dfsg-2 (embed)
658            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
659            - webcit <unfixed> (embed; bug #555219)
660            - asterisk 1:1.6.2.0~rc3-1 (embed)
661            - libjson-ruby 1.1.4-1 (embed; bug #555224)
662            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
663            - horde3 <unfixed> (embed)
664            - knowledgeroot <unfixed> (embed; bug #555230)
665            - mediatomb <unfixed> (embed; bug #555233)
666            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
667            - ebug-http <unfixed> (embed; bug #555236)
668            - phpgedview <removed> (embed)
669            - poker-network <unfixed> (embed; bug #555238)
670            - rails 2.1.0-6 (embed)
671            - wordpress 2.5.0-2 (embed; bug #555243)
672            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
673            TODO: search through all of the other zope packages
674            - ampache 3.4.1-2 (embed)
675            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
676            - hobix 0.5~svn20070319-4 (embed; bug #555247)
677            - zabbix 1.6.6-4 (embed; bug #555250)
678            - chora2 <unfixed> (embed; bug #555253)
679            - gollem <unfixed> (embed; bug # 555254)
680            - jscropperui 1.2.1-1 (embed; bug #555257)
681            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
682            - ingo1 <unfixed> (embed; bug #555261)
683            - kronolith2 <unfixed> (embed; bug #555262)
684            - activeldap <unfixed> (embed)
685            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
686            - mantis <unfixed> (embed; bug #555265)
687            - otrs2 2.3.4-6 (embed; bug #555267)
688            - webcalendar <unfixed> (embed; bug #555269)
689            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
690            - jifty 0.90519-1 (embed; bug #555271)
691            - jquery <unfixed> (embed; bug #555272)
692            - passenger 2.2.5debian1-1 (embed; bug #555273)
693            - plone3 <unfixed> (embed; bug #555275)
694            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
695            - libhtml-prototype-perl <unfixed> (embed; bug #538920)
696            - xulrunner <unfixed> (embed)
697            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
698    
699    gdb
700            - insight <unfixed> (embed)
701    
702    e2fsprogs
703            - ldiskfsprogs <unfixable> (fork)
704    
705    quazip (not packaged in Debian)
706            - qcake <unfixed> (embed)
707            NOTE: starting with upstream version 0.6.4
708    
709    exo
710            - pcmanfm <unfixed> (embed; bug #499677)
711            NOTE: slightly modified source code
712    
713    java
714            - openjdk-6 <unfixed>
715            - sun-java5 <unfixed>
716            - sun-java6 <unfixed>
717    
718    libphp-snoopy
719            - ampache 3.4.1-2 (embed; bug #504169)
720            - gforge 4.6.99+svn6094-2 (embed)
721            - mahara 1.0.5-2 (embed; bug #504170)
722            - pixelpost 1.7.1-5 (embed; bug #504171)
723            - mediamate 0.9.3.6-5 (embed; bug #504172)
724            - opendb <removed> (embed; bug #504173)
725            [etch] - opendb <unfixed> (embed; bug #504173)
726            - wordpress 2.5.1-9 (embed; bug #443948)
727            - moodle <unfixed> (embed; bug #507185)
728            [etch] - phpgroupware <unfixed> (embed)
729            NOTE: phpgroupware-felamimail
730            - magpierss 0.72-3 (embed; bug #431089)
731    
732    jquery
733            - zekr <unfixed> (embed)
734            - wordpress <unknown> (embed)
735            - yocto-reader <unfixed> (embed)
736            - textpattern <unfixed> (embed)
737            - genshi 0.5.1-1 (embed)
738            NOTE: compressed file under examples/ dir
739            - prewikka <unfixed> (embed)
740            - libramaze-ruby <unfixed> (embed)
741            - drupal5 <unfixed> (embed)
742            - b2evolution <unfixed> (embed)
743            - wesnoth <unfixed> (embed)
744    
745    tablesorter (jquery plugin, not packaged yet)
746            - wesnoth <unfixed> (embed)
747    
748    kses
749            - wordpress <unfixed> (embed; bug #504242)
750            NOTE: their copy has all methods renamed to wp_<foo>
751            NOTE: kses isn't in Debian, RFP: #504240
752            - moodle <unfixed> (embed; bug #507185)
753            - egroupware <unfixed> (embed)
754    
755    magpierss
756            - wordpress <unfixed> (embed; bug #504242)
757            - moodle <unfixed>
758    
759    php-gettext
760            - wordpress 2.8.4-1 (embed; bug #504242)
761    
762    libphp-ixr (name may change, it is the Incutio XML-RPC)
763            - wordpress <unfixed> (embed; bug #504242)
764            NOTE: libphp-ixr isn't in Debian, RFP: #504236
765            - dokuwiki <unfixed> (embed)
766            - textpattern <unfixed> (embed)
767    
768    libphp-cas
769            - glpi <unfixed> (embed)
770            - moodle <unfixed> (embed; bug #505984)
771    
772    scriptaculous (prototype.js is among the embeds in the following)
773            - glpi <unfixed> (embed)
774            - libaws <unfixed> (embed; bug #555222)
775            - op-panel <unfixed> (embed)
776            - symfony <unfixed> (embed)
777            NOTE: maintainer says there are extra incompatible changes required
778            - pixelpost 1.7.1-6 (embed)
779            - webhelpers <unfixed> (embed)
780            - qwik <unfixed> (embed; bug #555241)
781            - smokeping <unfixed> (embed)
782            - turba2 <unfixed> (embed)
783            - typo3-src 4.2.3-1 (embed)
784            - request-tracker3.6 <unfixed> (embed)
785            - request-tracker3.8 <unfixed> (embed)
786            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
787            - wordpress 2.5.0-2 (embed)
788    
789    libmarkdown-php
790            - moodle <unfixed> (embed; bug #507185)
791            - pixelpost 1.7.1-6 (embed)
792    
793    php-openid
794            - wordpress-openid <itp> (embed)
795    
796    geshi
797            - dokuwiki 0.0.20080505-3.1 (embed)
798            - pgfouine 1.0-1.1 (embed)
799            - websvn 2.1.0-1 (embed)
800    
801    webcalendar
802            - gforge 4.7~rc2-6 (embed; bug #504758)
803    
804    libical
805            - kdepim <unfixed> (fork)
806            - kdepimlibs <unfixed> (fork)
807            NOTE: fixed in KDE4 post 4.1.x series
808            - claws-mail-extra-plugins <unfixed> (fork)
809    
810    libltdl3
811            - kdelibs <unfixed> (embed)
812            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
813            - synfig <unfixed> (embed)
814    
815    harfbuzz
816            - qt4-x11 <unfixed> (embed)
817    
818    libzip
819            - php5 <unfixed> (fork)
820            - odt2txt <unfixed> (embed; bug #523808)
821    
822    json.php (not packaged; should be replaced with php's built-in functions)
823            - moodle <unfixed>
824            - yui <unfixed>
825            - gallery2 <unfixed>
826            - dokuwiki <unfixed>
827            - typo3-src <unfixed>
828    
829    php-fpdf
830            - tcpdf <itp> (fork)
831            - moodle <unfixed>
832            - phpwiki <unfixed>
833            - egroupware <unfixed>
834            - ldap-account-manager <unfixed> (fork)
835    
836    tcpdf (itp: #495985)
837            - moodle <unfixed>
838            - phpmyadmin <unfixed>
839    
840    typo3
841            - moodle <unfixed>
842    
843    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
844            - moodle <unfixed>
845            - gosa <unfixed>
846    
847    php-ole (itp: #487558)
848            - moodle <unfixed>
849    
850    pieforms (http://www.catalyst.net.nz)
851            - mahara <unfixed>
852    
853    savant2 (http://phpsavant.com)
854            - egroupware <unfixed>
855    
856    rssparser (http://nwow.org)
857            - egroupware <unfixed>
858            - phpgroupware <unfixed>
859    
860    lcms
861            - openjdk-6 <unfixed> (fork)
862    
863    libphp-phplayersmenu
864            - diogenes <unfixed>
865            - phpldapadmin <unfixed>
866    
867    libphp-pclzip
868            - docvert <unfixed>
869            - moodle <unfixed>
870            - egroupware <unfixed>
871    
872    libphp-simplepie
873            - dokuwiki <unfixed>
874    
875    libphp-jpgraph
876            - egroupware <unfixed>
877    
878    php-simpletest
879            - moodle <unfixed>
880    
881    libpng
882            - iceweasel <not-affected> (uses xulrunner)
883            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
884            - iceape 1.0.13~pre080614i-0etch1 (embed)
885            - xulrunner 1.9.0.13-1 (embed)
886            [lenny] - xulrunner 1.9.0.11-0lenny1
887            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
888            - gamera 3.2.3-1 (embed)
889    
890    irssi
891            - silc-client <unfixed> (embed)
892            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
893    
894    extc
895            - mtasc <unfixed> (embed)
896            - haxe <unfixed> (embed)
897    
898    swflib
899            - mtasc <unfixed> (embed)
900            - haxe <unfixed> (embed)
901    
902    libitext-java
903            - bouncycastle 2.1.4-1 (embed)
904    
905    python-ply
906            - pyke <unfixed> (embed; bug #555363)
907            - pywbem <unfixed> (embed; bug #555364)
908            - sepolgen <unfixed> (embed; bug #555365)
909            - zope-textindexng3 <unknown> (embed)
910            - iceweasel <not-affected> (uses xulrunner)
911            - xulrunner <unknown> (embed)
912            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
913    
914    libdumbnet (libdnet upstream)
915            - nmap <unfixed> (fork)
916    
917    gcc-4.4
918            - gcc-mingw32 <unfixed> (embed)
919    
920    camlimages
921            - advi <unfixed> (static; bug #550441)
922    
923    memcached
924            - memcachedb <unfixed> (embed)
925    
926    yajl
927            - argyll <unfixed> (embed; bug #544223)
928            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
929    
930    nusoap
931            - gforge 4.8.2-1 (embed)
932    
933    libept
934            - adept <unfixed> (embed; bug #540649)
935    
936    libvorbis
937            - iceweasel <not-affected> (uses xulrunner)
938            - xulrunner <unfixed> (embed; bug #540959)
939            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
940            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
941            - iceape <unfixed> (embed)
942            [etch] - iceape <not-affected> (introduced in 2.0)
943            [lenny] - iceape <not-affected> (introduced in 2.0)
944    
945    cairo
946            - iceweasel <not-affected> (uses xulrunner)
947            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
948    
949    liboggz
950            - iceweasel <not-affected> (uses xulrunner)
951            - xulrunner <unfixed> (embed)
952            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
953            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
954            - iceape <unfixed> (embed)
955            [etch] - iceape <not-affected> (introduced in 2.0)
956            [lenny] - iceape <not-affected> (introduced in 2.0)
957    
958    liboggplay
959            - iceweasel <not-affected> (uses xulrunner)
960            - xulrunner <unfixed> (embed)
961            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
962            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
963            - iceape <unfixed> (embed)
964            [etch] - iceape <not-affected> (introduced in 2.0)
965            [lenny] - iceape <not-affected> (introduced in 2.0)
966    
967    php-net-dnsbl
968            - serendipity <unfixed> (embed)
969    
970    php-onyx-rss
971            - serendipity <unfixed> (embed)
972    
973    php-text-wiki
974            - serendipity <unfixed> (embed)
975    
976    php-xml-rpc
977            - serendipity <unfixed> (embed)
978    
979    polarssl (does not have a shared library)
980            - pdkim <itp> (embed; bug #543150)
981            - xyssl <unfixed> (old-version)
982    
983    pidgin
984            - gaim <removed> (old-version)
985    
986    icu
987            - webkit 1.0.1-1 (embed; bug #547214)
988            - texlive-bin <unfixed> (fork)
989            NOTE: texlive upstream working with icu upstream to merge their changes
990    
991    cyrus-imapd-2.2
992            - kolab-cyrus-imapd <unfixed> (fork)
993            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
994    
995    python-cxx-dev
996            - freecad <unfixed> (embed; bug #547936)
997    
998    libzipios++-dev
999            - freecad <unfixed> (embed; bug #547941)
1000    
1001    linux-2.6
1002            - kvm <unfixed> (embed; bug #549973) [./kernel/*]
1003            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1004            - kernel-source-2.6.8 <removed> (old-version)
1005            - kernel-source-2.4.27 <removed> (old-version)
1006            - kernel-source-2.4.24 <removed> (old-version)
1007            - kernel-source-2.2.25 <removed> (old-version)
1008            - kernel-source-2.2.20 <removed> (old-version)
1009    
1010    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1011            - kvm <unfixed> (embed) [./libfdt/*]
1012    
1013    qweb (not packaged)
1014            - ajaxterm <unfixed>
1015    
1016    opensaml2
1017            - opensaml <removed> (old-version)
1018    
1019    shibboleth-sp2
1020            - shibboleth-sp <removed> (old-version)
1021    
1022    tuxonice-userui
1023            - suspend2-userui <removed> (old-version)
1024    
1025    expat
1026            - w3c-libwww <removed> (embed; bug #551941)
1027            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1028            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1029            - python2.5 <unfixed> (embed; bug #553403) [./Modules/expat/*]
1030            - python2.4 <unfixed> (embed; bug #553403)
1031            - wxwindows2.4 <removed> (embed)
1032            - wxwidgets2.6 <unfixed> (embed)
1033            - wxwidgets2.8 <unfixed> (embed)
1034            - celementtree <unfixed> (embed)
1035            - audacity <unfixed> (embed)
1036            - matanza <unfixed> (embed)
1037            - tdom <unfixed> (embed)
1038            - udunits <unfixed> (embed)
1039            - apr-util 1.2 (embed)
1040            - ayttm <unfixed> (embed)
1041            - cableswig <unfixed> (embed)
1042            - cadaver <unfixed> (embed)
1043            - cmake <unfixed> (embed)
1044            - coin3 <unfixed> (embed)
1045            - gdcm <unfixed> (embed)
1046            - ghostscript <unfixed> (embed)
1047            - grmonitor <unfixed> (embed)
1048            - iceape <unfixed> (embed)
1049            - insighttoolkit <unfixed> (embed)
1050            - libparagui1.1 <unfixed> (embed)
1051            - paraview <unfixed> (embed)
1052            - poco <unfixed> (embed)
1053            - simgear <unfixed> (embed)
1054            - sitecopy <unfixed> (embed)
1055            - smart 1.0-1 (embed)
1056            [etch] - smart <unfixed> (embed)
1057            - swish-e <unfixed> (embed)
1058            - tla <unfixed> (embed)
1059            - vtk <unfixed> (embed)
1060            - wbxml2 <unfixed> (embed)
1061            - xmlrpc-c <unfixed> (embed)
1062            - iceweasel <unfixed> (embed)
1063            - kompozer <unfixed> (embed)
1064            - vxl <unfixed> (embed)
1065            - xulrunner <unfixed> (embed)
1066            - apache2 2.2 (embed)
1067            - texlive-bin <unfixed> (embed) [included twice]
1068            - vnc4 <unfixed> (embed)
1069            - xotcl <unfixed> (embed)
1070    
1071    xerces-c
1072            - xerces-c2 <unfixed> (old-version)
1073            - xerces27 <removed> (old-version)
1074    
1075    md5 (RSA's version; not the gnu version provided by coreutils)
1076            - w3c-libwww <removed> (embed; bug #551942)
1077            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1078    
1079    enet
1080            - sauerbraten <unfixed> (embed; #497194)
1081    
1082    eglibc
1083            - glibc <removed> (old-version)
1084    
1085    galib
1086            - gamera 3.2.3-1 (embed)
1087    
1088    configobj
1089            - bzr <unfixed> (embed; bug #555336)
1090            - elisa <unfixed> (embed; bug #555337)
1091            - gaupol <unfixed> (embed; bug #555338)
1092            - ipython <unfixed> (embed; bug #555339)
1093            - pida <unfixed> (embed; bug #555340)
1094            - psychopy <unfixed> (embed; bug #555341)
1095            - rest2web <unfixed> (embed; bug #555342)
1096            - auth2db <unknown> (embed)
1097            - dynagen <unknown> (embed)
1098            - iceweasel <unknown> (embed)
1099            - sabnzbdplus <unknown> (embed)
1100            - xulrunner <unknown> (embed)
1101            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1102    
1103    python-clientform
1104            - bibus <unfixed> (embed; bug #555332)
1105            - zope2.10 <unfixed> (embed; bug #555333)
1106            - zope2.11 <unfixed> (embed; bug #555334)
1107            - python-mechanize <unknown> (embed)
1108            - twill <unknown> (embed)
1109    
1110    python-mechanize
1111            - zope2.10 <unfixed> (embed; bug #555337)
1112            - zope2.11 <unfixed> (embed; bug #555338)
1113            - twill <unknown> (embed; bug #555339)
1114    
1115    pexpect
1116            - duplicity 0.6.06-1 (embed; bug #555361)
1117            - hplip <unfixed> (embed; bug #555362)
1118            - smart <unfixed> (embed; bug #555363)
1119    
1120    pyparsing
1121            - bauble <unfixed> (embed; bug #555366)
1122            - boa-constructor 0.6.1-8 (embed; bug #555367)
1123            - calibre <unfixed> (embed; bug #555368)
1124            - matplotlib <unfixed> (embed; bug #531024)
1125            - zhpy <unfixed> (embed; bug #555370)
1126            - polybori <unknown> (embed)
1127            - python-whoosh <unknown> (embed)
1128            - twill <unknown> (embed)
1129            - zope-textindexng3 <unknown> (embed)
1130    
1131    python-pysqlite2
1132            - python2.4 <unfixed> (embed; bug #553403)
1133            - python2.5 <unfixed> (embed; bug #553403)
1134    
1135    celementtree
1136            - python2.5 <unfixed> (embed)
1137            - smart 1.0-1 (embed)
1138            [etch] - smart <unfixed> (embed)
1139    
1140    elementtree
1141            - python2.5 <unfixed> (embed)
1142            - bzr <unfixed> (embed; bug #555343)
1143            - gedit 2.28.2-1 (embed; bug #555344)
1144            - smart 1.0-1 (embed)
1145            [etch] - smart <unfixed> (embed)
1146            - solfege <unfixed> (embed; bug #555345)
1147            - w3af <unfixed> (embed; bug #555346)
1148            - python-qt4 <unknown> (embed)
1149            - sphinx <unknown> (embed)
1150            - python-nltk <itp> (embed)
1151    
1152    python2.5
1153            - python2.4 <unfixed> (old-version)
1154            - jython <unfixed> (embed)
1155            NOTE: embeds many stdlib modules
1156            - python-django <unfixed> (embed; bug #555419)
1157            NOTE: embeds stdlib modules: doctest, decimal
1158            - gamera 3.2.3-1 (embed)
1159            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1160            - boa-constructor <unfixed> (embed; bug #555426)
1161            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1162            - nicotine <unfixed> (embed; bug #555427)
1163            NOTE: embeds stdlib modules: ConfigParser
1164            - museek+ <unfixed> (embed; bug #555428)
1165            NOTE: embeds stdlib modules: ConfigParser
1166            - vegastrike-data <unfixed> (embed)
1167            NOTE: embeds many stdlib modules
1168            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1169            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1170            - config-manager <unfixed> (embed; bug #555423)
1171            NOTE: embeds stdlib modules: optparse
1172            - jhbuild 2.28.0-1 (embed; bug #555421)
1173            NOTE: embeds stdlib modules: optparse, subprocess
1174            - smart <unfixed> (embed; bug #555432)
1175            NOTE: embeds stdlib modules: optparse
1176            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1177            NOTE: embeds stdlib modules: doctest
1178            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1179            NOTE: embeds stdlib modules: doctest
1180            - distribute <unfixed> (embed)
1181            NOTE: embeds stdlib modules: doctest
1182            - python-setuptools <unfixed> (embed; bug #555435)
1183            NOTE: embeds stdlib modules: doctest
1184            - zope.testing <unfixed> (embed; bug #555436)
1185            NOTE: embeds stdlib modules: doctest
1186            - translate-toolkit <unfixed> (embed; bug #555422)
1187            NOTE: embeds stdlib modules: textwrap, contextlib
1188            - libtpclient-py <unfixed> (embed; bug #555424)
1189            NOTE: embeds stdlib modules: subprocess
1190            - grass <unfixed> (embed; bug #555425)
1191            NOTE: embeds stdlib modules: subprocess
1192            - coherence <unfixed> (embed; bug #555429)
1193            NOTE: embeds stdlib modules: uuid
1194            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1195            NOTE: embeds stdlib modules: uuid
1196            - setroubleshoot <unfixed> (embed; bug #555431)
1197            NOTE: embeds stdlib modules: uuid
1198            - linkchecker <unfixed> (embed; bug #555414)
1199            NOTE: embeds msgfmt.py script
1200            - imdbpy <unfixed> (embed)
1201            NOTE: embeds msgfmt.py script
1202            - kiwi <unfixed> (embed)
1203            NOTE: embeds msgfmt.py script
1204            - moin <unfixed> (embed)
1205            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1206            - plone3 <unfixed> (embed)
1207            NOTE: embeds msgfmt.py script
1208            - roundup <unfixed> (embed)
1209            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1210            - rednotebook <unfixed> (embed; bug #555415)
1211            NOTE: embeds msgfmt.py script
1212            - turbogears <unfixed> (embed)
1213            NOTE: embeds msgfmt.py script
1214            - elisa <unfixed> (embed)
1215            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1216            - calibre <unfixed> (embed)
1217            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1218            - mailman <unfixed> (embed; #555416)
1219            NOTE: embeds msgfmt.py script
1220            - python-docutils <unknown> (embed)
1221            NOTE: embeds stdlib modules: optparse, textwrap
1222            - python-imaging <unknown> (embed)
1223            NOTE: embeds stdlib modules: doctest
1224            - python-mechanize <unknown> (embed)
1225            NOTE: embeds stdlib modules: doctest
1226            - twill <unknown> (embed)
1227            NOTE: embeds stdlib modules: subprocess
1228            - zeroc-ice <unknown> (embed)
1229            NOTE: embeds stdlib modules: subprocess
1230            - wxwidgets2.8 <unknown> (embed)
1231            NOTE: embeds stdlib modules: subprocess
1232            - cycle <unknown> (embed)
1233            NOTE: embeds msgfmt.py script
1234            - deluge <unknown> (embed)
1235            NOTE: embeds msgfmt.py script
1236            - opendict <unknown> (embed)
1237            NOTE: embeds msgfmt.py script
1238            - openerp-client <unknown> (embed)
1239            NOTE: embeds msgfmt.py script
1240            - rapidsvn <unknown> (embed)
1241            NOTE: embeds msgfmt.py script
1242            - wammu <unknown> (embed)
1243            NOTE: embeds msgfmt.py script
1244            - gaphor <unknown> (embed)
1245            NOTE: embeds msgfmt.py script
1246            - pida <unknown> (embed)
1247            NOTE: embeds msgfmt.py script
1248            - python-formencode <unknown> (embed)
1249            NOTE: embeds msgfmt.py script
1250            - duplicity <unfixed> (embed)
1251            NOTE: embeds stdlib module: urlparse, tarfile
1252            - pygopherd <unfixed> (embed)
1253            NOTE: embeds stdlib module: zipfile
1254    
1255    argparse
1256            - twill <unfixed> (embed; bug #555347)
1257            - ipython <unfixed> (embed; bug #555348)
1258    
1259    coherence
1260            - elisa <unfixed> (embed; bug #555335)
1261    
1262    simpletal
1263            - plastex <unfixed> (embed; bug #555371)
1264    
1265    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1266            - postr <unfixed> (embed)
1267            - elisa <unfixed> (embed)
1268    
1269    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1270            - apertium-tolk <unfixed> (embed)
1271            - ipython <unfixed> (embed)
1272            - virtaal <unfixed> (embed)
1273    
1274    distribute
1275            - setuptools <removed> (old-version)
1276    
1277    rails
1278            - jruby1.2 <unfixed> (embed) [./bench/rails/*]
1279            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1280            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1281            - thin <unfixed> (embed) [./spec/rails_app/*]
1282            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1283            NOTE: be dangerous if developers are naively basing their code off of the examples
1284            NOTE: prototype.js is among the example files
1285    
1286    lucene2 (prototype.js is among the embeds in the following)
1287            - lucene <unfixed> (old-version)
1288            - pylucene <unfixed> (embed)
1289            - libpdfbox-java <unfixed> (embed)
1290            - libfontbox-java <unfixed> (embed)
1291            - libjempbox-java <unfixed> (embed)
1292            - solr <unfixed> (embed)
1293    
1294    unicode-data
1295            - syslinux <unfixed> (embed)
1296            - camomile <unfixed> (embed)
1297            - fribidi <unfixed> (embed)
1298            - m17n-db <unfixed> (embed)
1299            - sbcl <unfixed> (embed)
1300            - heimdal <unfixed> (embed)
1301            - icu <unfixed> (embed)
1302            - icu4j <unfixed> (embed)
1303            - krb5 <unfixed> (embed)
1304            - moodle <unfixed> (embed)
1305            - openldap <unfixed> (embed)
1306            - pike7.6 <unfixed> (embed)
1307            - samba <unfixed> (embed)
1308            - samba4 <unfixed> (embed)
1309            - cmucl <unfixed> (embed)
1310            - typo3-src <unfixed> (embed)
1311            - mauve <unfixed> (embed)
1312            - texlive-bin <unfixed> (embed)
1313            - ypsilon <unfixed> (embed)
1314            - jeuclid <unfixed> (embed)
1315            - charmap.app <unfixed> (embed)
1316            - clisp <unfixed> (embed)
1317            - gnulib <unfixed> (embed)
1318            - opensrs-client <unfixed> (embed)
1319            - saxonb <unfixed> (embed)
1320            - rails <unfixed> (embed)
1321    
1322    feedparser
1323            - rawdog <unfixed> (embed; bug #383422)
1324            - miro <unfixed> (embed; bug #555351)
1325            - calibre <unfixed> (embed; bug #555352)
1326            - freevo <unfixed> (embed; bug #555353)
1327            - pida <unfixed> (embed; bug #555354)
1328            - planet-venus <unfixed> (embed; bug #555355)
1329            - plone3 <unfixed> (embed; bug #555356)
1330            - exaile 0.2.14+debian-1 (embed)
1331            - screenlets 0.1.2-3 (embed)
1332            NOTE: included twice
1333    
1334    agg:
1335            - matplotlib <unfixed> (embed: bug #377271)
1336            - contextfree <unfixed> (embed)
1337            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1338            - exactimage <unfixed> (embed)
1339            - python-enable <unfixed> (embed)
1340            - mapnik 0.5.1-3 (embed)
1341            NOTE: links statically to agg, but shared library is not available (bug #377271)
1342    
1343    vtk
1344            - paraview <unfixable> (embed; bug #495426)
1345    
1346    txt2tags
1347            - rednotebook <unfixed> (embed)
1348    
1349    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1350            - gajim <unfixed> (embed)
1351            - emesene <unfixed> (embed)
1352            - convirt <unfixed> (embed)
1353            - pida <unfixed> (embed)
1354            - rednotebook <unfixed> (embed)
1355    
1356    horde3 (prototype.js is among the embeds in the following)
1357            - mnemo2 <unfixed> (embed)
1358            - nag2 <unfixed> (embed)
1359    
1360    cimg
1361            - gmic <itp> (embed)
1362    
1363    mootools
1364            - gmic <itp> (embed)
1365    
1366    openldap
1367            - openldap2.3 <removed> (old-version)
1368    
1369    grub2
1370            - grub <unfixed> (old-version)
1371    
1372    gnupginterface
1373            - duplicity <unfixed> (embed)
1374    
1375    python-dateutil
1376            - awn-extras-applets <unfixed> (embed)
1377            - matplotlib <unknown> (embed)
1378    
1379    cups
1380            - cupsys <removed> (old-version)
1381    
1382    yui
1383            - bcfg2 <not-affected> (present in source but not included in any binary files)
1384            - serendipity <unfixed> (embed; bug #557746)
1385            - moodle 1.8.2.dfsg-5 (embed)
1386            - jifty <unfixed> (embed; bug #557748)
1387            - webgui 7.7.26-1 (embed)
1388            - loggerhead 1.17-1 (embed)
1389    
1390    quake3 (vanilla source not packaged in debian)
1391            - openarena <unfixable> (fork)
1392    
1393    quake2 (vanilla source not packaged in debian)
1394            - alien-arena <unfixable> (fork)
1395            - warsow <unfixable> (fork)
1396    
1397    libtheora
1398            - iceweasel <not-affected> (uses xulrunner)
1399            - xulrunner <unfixed> (embed)
1400            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1401            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1402            - iceape <unfixed> (embed; bug #559276)
1403            [etch] - iceape <not-affected> (introduced in iceape 2.0)
1404            [lenny] - iceape <not-affected> (introduced in iceape 2.0)

Legend:
Removed from v.7841  
changed lines
  Added in v.13435

  ViewVC Help
Powered by ViewVC 1.1.5