/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7923 by stef-guest, Mon Jan 14 21:43:39 2008 UTC revision 14828 by jmm-guest, Mon Jun 7 22:57:20 2010 UTC
# Line 1  Line 1 
1  Embedded code copies  Embedded code copies
2  ====================  ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects which is considered bad for fixing security flaws  This is considered bad for fixing security flaws because the fix needs
6  because the fix needs to be applied in multiple source packages.  to be applied in multiple source packages.
7    
8  Format:  Format:
9  <srcpkg> (<optional comment about srcpkg>)  <srcpkg> (<optional comment about srcpkg>)
10          - <embedding srcpkg> <status> (<sort>; bug #<number>)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11          NOTE: optional comments about the linkage of the embedding srcpkg          NOTE: optional comments about the linkage of the embedding srcpkg
12    
13  status: version number fixing the embedded copy, <unfixed>, <removed>, <itp> or <unknown> if the version number can not be determined  status: version number fixing the embedded copy
14            <unfixed> if the issue is not yet fixed
15            <removed> if the package was removed from the archive
16            <itp> if the package is in the process of being packaged
17            <not-affected> if the package does not use the embedded copy
18            <unknown> if the version number can not be determined
19            <unfixable> for unavoidable cases (e.g., forks that add real value)
20  sort: static (linking statically against a lib)  sort: static (linking statically against a lib)
21        embed (embedding a copy of the library into another source package)        embed (embeds a copy of the library into another source package)
22        fork (the package is not just embedding code but it is a fork and thus might share parts of the source code)        modified-embed (embeds a code copy that differs from upstream code)
23          fork (a full-blown fork of another source package)
24          old-version (an older version of essentially the same code)
25    
26  The srcpkg might be some string to identify the code if there is no specific source package.  The srcpkg might be some string to identify the code if there is no
27    specific source package.
28    
29  Everything up to the next line is ignored  Everything up to the next line is ignored.
30  ---BEGIN  ---BEGIN
31  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
32          NOTE: Fixed packages link to poppler library unless otherwise noted          NOTE: Fixed packages link to poppler library unless otherwise noted
         - gpdf <removed>  
         [sarge] - gpdf <unfixed>  
         NOTE: has been replaced by evince in etch  
33          - pdftohtml <unknown>          - pdftohtml <unknown>
34          [sarge] - pdftohtml <unfixed>          [sarge] - pdftohtml <unfixed>
35          [etch] - pdftohtml <unfixed>          [etch] - pdftohtml <unfixed>
36          NOTE: has been replaced by poppler-utils          NOTE: has been replaced by poppler-utils
37          - kdegraphics <unfixed> (embed; bug #436164)          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
38          NOTE: the kpdf replacement in KDE 4 is using poppler          - texlive-base 3.0-12 (embed)
         - tetex-bin 3.0-12 (embed)  
39          - texlive-bin 2007-1 (embed)          - texlive-bin 2007-1 (embed)
40          NOTE: links to poppler          - koffice 1:2.0.0-1 (embed; bug #436163)
         - koffice <unfixed> (embed; bug #436163)  
41          - libextractor 0.5.12-1 (embed)          - libextractor 0.5.12-1 (embed)
42          NOTE: libextractor is using its own pdf decoder now          NOTE: libextractor is using its own pdf decoder now
         - libextractor 0.5.12-1 (embed)  
         - pdfkit.framework 0.8-4 (embed)  
43          - ipe <unfixed> (embed)          - ipe <unfixed> (embed)
44          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
45          - ruby-gnome2 <unknown> (embed)          - ruby-gnome2 <unknown> (embed)
46          NOTE: copy only present in source but links to poppler          - pdfedit <unfixed> (embed; bug #510794)
47            - swftools <removed> (embed; bug #551293)
48            - poppler <unfixable> (fork)
49    
50  ppmd  ppmd
51          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)          - libcomplearn-mod-ppmd <unfixed> (fork)
52            NOTE: discussion in #458152
53    
54    libevent
55            - transmission 1.71-1 (embed; bug #529372)
56    
57    lrmi
58            - read-edid 2.0.0-1 (embed; bug #495131)
59            - s3switch <unfixed> (embed)
60            - xresprobe <unfixed> (embed)
61            - zhcon <unfixed> (embed)
62    
63    peercast
64            - gnome-peercast <removed> (embed)
65            [etch] - gnome-peercast <unfixed> (embed)
66    
67  silc-toolkit  silc-toolkit
68          - silc-client 1.1~beta6-1 (embed)          - silc-client 1.1~beta6-1 (embed)
69    
70    icclib
71            - ghostscript <unfixed> (embed)
72            - argyll <unfixed> (embed)
73    
74    libusb
75            - argyll <unfixed> (embed)
76    
77  dietlibc  dietlibc
78          - ccontrol 0.9.1+20071204-1 (static)          - ccontrol 0.9.1+20071204-1 (static)
79    
80    libmikmod
81            - sdl-mixer1.2 <unfixed> (embed)
82            TODO: report bug
83    
84  libiax  libiax
85          - iaxmodem <unfixed> (embed)          - iaxmodem <unfixable> (embed; bug #548885)
86    
87    spandsp
88            - iaxmodem <unfixable> (embed; bug #548885)
89    
90    python-paramiko
91            - fabric 0.9.0-2 (embed; bug #561398)
92    
93  zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
94          - dpkg <unfixed> (embed)          - dpkg 1.15.6 (static)
95          NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion          NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
96          - rsync <unfixed> (embed)          - rsync <unfixed> (embed)
97            - cherokee <unfixed> (embed)
98          NOTE: somehow derived code base          NOTE: somehow derived code base
99          - mono <unfixed> (embed)          - mono <unfixed> (embed)
100          TODO: check mozilla          TODO: check mozilla
# Line 67  zlib (lots of apps embed a copy, but lin Line 103  zlib (lots of apps embed a copy, but lin
103          - mrtg 2.12.2-1 (embed)          - mrtg 2.12.2-1 (embed)
104          - rpm <unknown> (embed)          - rpm <unknown> (embed)
105          NOTE: pinged anibal since when rpm was fixed          NOTE: pinged anibal since when rpm was fixed
106            - tuxcmd-modules <unfixed> (embed)
107            - zsync <unfixed>
108            - tra <unfixed>
109            - sash <unfixed>
110            - nsis <unfixed>
111            - mseide-msegui <unfixed>
112            NOTE: mseide
113            - mirrordir <unfixed>
114            - poco <unfixed>
115            - klibc <unfixed>
116            - emboss <unfixed>
117            - ghostscript <unfixed>
118            - freeimage <unfixed>
119            - clamav <unfixed> (fork)
120            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
121            - tuxonice-userui <unfixed> (static)
122            - plt-scheme <unfixed>
123            - perl <unfixed>
124            - paraview <unfixed>
125            - velvet 0.7.56~nozlibcopy-1
126            - gcvs <unfixed>
127            - dump <unfixed>
128            - aide <unfixed> (static)
129            - dar <unfixed> (static)
130            - avfs <unfixed>
131            - fpc <unfixed>
132            - winff <unfixed>
133            NOTE: inherited from fpc, see #472304
134            - lazarus <unfixed>
135            NOTE: inherited from fpc, see #472304
136            - erlang <unfixed> (embed)
137            - gamera 3.2.3-1 (embed)
138            - python2.4 <unfixed> (embed; bug #553403)
139            - python2.5 <unfixed> (embed; bug #553403)
140            - texlive-bin <unknown> (embed)
141    
142    dulwich
143            - hg-git 0.1.0-1 (embed; bug #541996)
144    
145    libvigraimpex
146            - hugin <unfixed> (embed; bug #542259)
147            - enblend-enfuse <unfixed> (embed; bug #542258)
148            - gamera 3.2.3-1 (embed)
149    
150  libbz2  libbz2
151          - dpkg <unfixed> (static)          - dpkg 1.15.6 (static)
152            - amd64-libs <unfixed> (static)
153  ekg          NOTE: let's call it "static"
154          - centericq <unfixed> (embed)          - dar <unfixed> (static)
155          - gaim <unfixed> (embed)          - dump <unfixed> (static)
156          - pigdin <unfixed> (embed)(links dynamically against libgadu)          - unalz <unfixed> (embed)
157          - kopete 4:3.3.2-5 (embed)          NOTE: has code, by the maint, to use the system version but links against the internal copy
158          - kadu <unfixed> (embed)  
159          - gadu <unfixed> (embed)  libyahoo2
160          NOTE: g/kadu not packaged in Debian yet          - centerim <unfixed> (embed; bug #559783)
161    
162    libmsn
163            - centerim <unfixed> (embed; bug #559783)
164    
165    libgadu
166            - centerim <unfixed> (embed; bug #559783)
167            - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
168            - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
169            - kdenetwork 4:3.3.2-5 (embed)
170            NOTE: from kdenetwork: kopete
171            - ekg 1:1.8~rc0-1 (embed)
172            - kadu 0.6.0.2-3 (embed; bug #504430)
173            - gadu <itp> (embed)
174    
175  xmlrpc (which package is the "origin" of this code?)  xmlrpc (which package is the "origin" of this code?)
176          - drupal <unfixed> (embed)          - drupal <unfixed> (embed)
177          - phpgroupware <unfixed> (embed)          - phpgroupware <unfixed> (embed)
178          - egroupware <unfixed> (embed)          - egroupware <unfixed> (embed)
179          - phpwiki (embed)          - phpwiki <unfixed> (embed)
180          - php4 <unfixed> (embed)          - php4 <removed> (embed)
181          TODO: check, php-pear, IIRC this was reorganized some weeks ago?          TODO: check, php-pear, IIRC this was reorganized some weeks ago?
182    
183  shtool (affects build-time only)  shtool (affects build-time only)
184          - mysql-ocaml <unfixed> (embed)          - mysql-ocaml <unfixed> (embed)
185          - php4 <unfixed> (embed)          - php4 <removed> (embed)
186            - php5 <unfixed> (embed)
187    
188  mozilla source code  xulrunner
189          - mozilla-firefox <unfixed> (embed)          - iceape <unfixed> (embed; bug #561749)
190          - mozilla-thunderbird          - iceweasel 2.0.0.19 (embed)
191          - firefox <removed>          - icedove <unfixed> (embed; bug #561750)
192          [etch] - firefox <unfixed> (embed)          - kompozer <unfixed> (embed; bug #532168)
193          - thunderbird <removed>          - galeon 2.0.2-4 (embed)
194          [etch] - thunderbird <unfixed> (embed)          - epiphany-browser 2.14.3-8 (embed)
195          - iceweasel <unfixed> (embed)          - conkeror 0.9~git080629-2 (embed)
196          - iceape <unfixed> (embed)          - kazehakase 0.4.2-1 (embed)
         - icedove <unfixed> (embed)  
         - xulrunner <unfixed> (embed)  
         - nvu <removed> (embed)  
197    
198  xli  xli
199          - xloadimage <unfixed> (embed)          - xloadimage <unfixed> (embed)
200    
201  lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
202          - openmotif <unfixed> (embed)          - openmotif <unfixed> (embed)
203          - xfree86/xorg <unfixed> (embed)  
204          NOTE: in libxpm  libxpm
205            - lesstif <unfixed> (embed; bug #575750)
206    
207  kerberized apps with BSD origin  kerberized apps with BSD origin
208          - krb4 <unfixed> (embed)          - krb4 <removed> (embed)
209          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
210          - heimdal <unfixed> (embed)          - heimdal <unfixed> (embed)
211    
212  grip (which pkg is the origin?)  grip (which pkg is the origin?)
213          - libcdaudio          - libcdaudio <unfixed>
214          - grip          - grip <unfixed>
215          - gnome-vfs          - gnome-vfs <unfixed>
216          TODO: check vfs2 as well          TODO: check vfs2 as well
217    
218  fudforum  fudforum
219          - phpgroupware-fudforum <unfixed> (embed)          [etch] - phpgroupware <unfixed> (embed)
220          - egroupware-fudforum <removed>          NOTE: phpgroupware-fudforum
221          [sarge] - egroupware-fudforum <unfixed> (embed)          [sarge] - egroupware-fudforum <removed> (embed)
222    
223    libbsd
224            - rdate 1:1.2-3 (embed)
225            - atheme-services <unfixed>
226            - libbsd-arc4random-perl <unfixed>
227            - isakmpd <unfixed>
228            - bsdgames <unfixed> (embed)
229            - bsd-mailx <unfixed> (embed)
230            - netcat-openbsd <unfixed> (embed; bug #550611)
231            - openssh <unfixed> (embed)
232            - unworkable <unfixed> (embed)
233    
234  cvs  cvs
235          - gcvs <unfixed> (embed)          - gcvs <unfixed> (embed)
236          NOTE: see cvsunix/src in tarball          NOTE: see cvsunix/src in tarball
237    
238  pcre  pcre3
239          - python* <unfixed> (embed)          - php4 <removed> (embed)
         - php4 <unknown> (embed)  
240          - analog 2:5.23-0woody1 (embed)          - analog 2:5.23-0woody1 (embed)
241          - libgoffice-1 <unfixed> (embed)          - goffice <unfixed> (embed)
242            NOTE: libgoffice-*
243          - vfu 4.06-4.1 (embed; bug #450754)          - vfu 4.06-4.1 (embed; bug #450754)
244          - tf5 5.0beta7-1 (embed)          - tf5 5.0beta7-1 (embed)
245          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
246          NOTE: this only affects versions >= 0.37          NOTE: this only affects versions >= 0.37
247          - glib <unfixed> (embed)          - glib2.0 2.15.2-1 (embed)
         NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic  
248          - apache2 2.0.53-4 (embed)          - apache2 2.0.53-4 (embed)
249          - exim4 4.10-0.srh20.12 (embed)          - exim4 4.10-0.srh20.12 (embed)
250          - yacas <unfixed> (embed)          - yacas <unfixed> (embed)
251          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
252          - gtamsanalyzer.app 0.42-5 (embed)          - gtamsanalyzer.app 0.42-5 (embed)
253            - tin 980117-1 (embed)
254            - kazehakase 0.5.2-1
255            - webkit 1.0.1-1 (embed)
256            - qt4-x11 <unfixed> (embed)
257            NOTE: embedded via webkit copy
258            - erlang <unfixed> (embed)
259            - ssed <unfixed> (embed)
260            - ircd-hybrid <unfixed> (static)
261            - emboss <unfixd>
262            - cherokee <unfixed> (embed)
263            - oftc-hybrid <unfixed> (embed)
264            - ratbox-services <unfixed> (embed)
265            - squeak-vm <unfixed> (embed)
266            - tinymux <unfixed> (embed)
267    
268  tiff  tiff
269          - wxpythongtk <unfixed> (embed)          - wxwindows2.4 2.2.1 (embed)
270          TODO: check, which debian pkg this is in          - gamera 3.2.3-1 (embed)
271            - freeimage <unfixed> (embed)
272            - libtk-img <unfixed> (embed)
273            NOTE: there are two copies, one under tiff/ other under libtiff/
274            - gdal <unfixed>
275    
276  uudeview  uudeview
277          - libconvert-uulib-perl <unfixed> (embed)          - libconvert-uulib-perl <unfixed> (embed)
278            - pan <unfixed> (embed)
279    
280  sqlite (not affected by security vulnerabilities so far)  sqlite (not affected by security vulnerabilities so far)
281          - amarok <unfixed> (embed)          - amarok <unfixed> (embed)
282          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
283          - iceweasel <unfixed> (embed)          - iceweasel <unfixed> (embed)
284            - heimdal <unfixed> (embed; bug #559616)
285    
286  util-linux/mount  util-linux/mount
287          - loop-aes-utils <unfixed> (embed)          - loop-aes-utils <unfixed> (embed)
288          NOTE: contains code from util-linux' mount in the mount-aes-udeb          NOTE: contains code from util-linux' mount in the mount-aes-udeb
289    
 webmin  
         - usermin <unknown> (embed)  
         [sarge] - usermin <unfixed> (embed)  
   
290  sylpheed  sylpheed
291          - sylpheed-claws <unfixed> (fork)          - sylpheed-claws <unfixed> (fork)
292    
# Line 184  phpldapadmin Line 301  phpldapadmin
301  chmlib  chmlib
302          - kchmviewer <unknown> (embed)          - kchmviewer <unknown> (embed)
303    
304  libavcodec/libavformat (source: ffmpeg)  ffmpeg (libavcodec/libavformat)
305          - mplayer <unfixed> (embed; bug #395252)          - mplayer 1.0~rc2-14 (embed; bug #395252)
306          - xvidcap <unfixed> (embed)          - kino 1.0.0-1
307          - kino <unfixed> (static)          - vlc <not-affected> (Links dynamically since initial release)
308          - vlc <unfixed> (static)          - smilutils 0.3.0-10
309          - smilutils <unfixed> (static)          NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
310          - motion <unfixed> (static)          - motion 3.1.19-1
311          - gst-ffmpeg <unfixed> (embed)          - gstreamer0.10-ffmpeg 0.10.3-2
312          - gstreamer0.10-ffmpeg <unfixed> (embed)          - xmovie <removed> (static)
         - xmovie <unfixed>  
313          TODO: gimp-gap (potentially using ffmpeg code as well)          TODO: gimp-gap (potentially using ffmpeg code as well)
314            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
315            - audacity 1.3.7-2 (embed; bug #512278)
316    
317    faad2
318            - mplayer 1.0~rc2-20 (embed)
319            - avifile <unfixed> (embed; bug #538750)
320            - ffmpeg-debian <removed> (embed)
321    
322  mad MPEG decoding lib  libmad (MPEG decoding lib)
         - mad <unfixed> (embed)  
323          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
324            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
325            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
326    
327  libdts  libdts
328          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
# Line 210  liba52 Line 334  liba52
334          - a52dec <unfixed> (embed)          - a52dec <unfixed> (embed)
335          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
336    
337  libmpeg2  mpeg2dec (libmpeg2)
         - mpeg2dec <unfixed> (embed)  
338          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
339    
340  curl  libmpeg3
341          - wget <unfixed> (embed)          - squeak-vm <unfixed> (embed)
342          NOTE: code for NTLM authentication  
343    libntlm
344            - wget <unfixed> (fork; bug #550436)
345            - curl <unfixed> (fork; bug #550437)
346            - cntlm <unfixed> (fork; bug #550438)
347    
348  uw-imap  uw-imap
349          - pine <unfixed> (embed)          - pine <unfixed> (embed)
# Line 225  uw-imap Line 352  uw-imap
352  imagemagick  imagemagick
353          - graphicsmagick <unfixed> (fork)          - graphicsmagick <unfixed> (fork)
354    
355    python-urlgrabber
356            - mercurial <unfixed> (embed; bug #531062)
357            - w3af <unfixed> (embed; bug #555372)
358            [experimental] - harvestman <unfixed> (embed; bug #555373)
359    
360    beautifulsoup
361            - python-mechanize <unfixed> (embed; bug #555349)
362            - zope2.11 <removed> (embed; bug #555350)
363            - twill <unknown> (embed)
364    
365  halibut  halibut
366          - nsis <unfixed> (embed)          - nsis <unfixed> (fork)
367    
368  libghttp  libghttp
369          - hotway <unfixed> (embed)          - hotway <unfixed> (embed)
370    
371  libsndfile  libsndfile
372          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
373    
374  glibmm2.4  glibmm2.4
375          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
376    
377  libgnomecanvasmm2.6  libgnomecanvasmm2.6
378          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
379    
380  libsigc++-2.0  libsigc++-2.0
381          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
382    
383  soundtouch  soundtouch
384          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
385    
386  libmms  libmms
387          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
388          - mimms <unfixed> (embed)          - mimms <unfixed> (embed)
389    
390  fckeditor  fckeditor
391          - knowledgeroot <unfixed> (embed)          - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
392          - moin <unfixed> (embed; bug #452599)          - moin 1.8.2-2 (embed; bug #452599)
393          - karrigell <unfixed> (embed; bug #452598)          - karrigell <removed> (embed; bug #452598)
394          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)          - gforge 4.6.99+svn6225-1 (embed)
395            - request-tracker3.8 <unfixed> (embed)
396            - otrs2 <unfixed> (embed)
397    
398  ipatlas (not packaged in Debian)  ipatlas (not packaged in Debian)
399          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
400    
401  libphp-phpmailer  libphp-phpmailer
402          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
403            - mahara <unfixed> (embed)
404            - symfony <unfixed> (embed; bug #566778)
405            [etch] - phpgroupware <unfixed> (embed)
406            NOTE: phpgroupware-felamimail is only in etch
407            - egroupware <unfixed> (embed; bug #504283)
408            - glpi <unfixed>
409    
410  htmlArea (not packaged in Debian)  htmlArea (not packaged in Debian)
411          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
412    
413  bennu (not packaged in Debian)  giflib
414          - moodle <unfixed> (embed)          - wine <unfixed> (embed; bug #466181)
415    
416  smarty:  bennu (not packaged in Debian, http://bennu.sourceforge.net)
417          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
418    
419    smarty
420            - moodle 1.8.2-2 (embed; bug #471158)
421            - gallery2 2.2.5-2 (embed; bug #471160)
422            - mahara 0.9.2-2 (embed; bug #471201)
423            - gosa 2.4beta1-1 (embed; bug #471200)
424    
425  TinyMCE  TinyMCE
426          - wordpress <unfixed> (embed)          - wordpress 2.5.1-3 (embed; bug #478257)
427          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
428          - knowledgeroot <unfixed> (embed)          - knowledgeroot <unfixed> (embed)
429          - joomla <itp> (bug #326398)          - joomla <itp> (bug #326398)
430    
431  scintilla  scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
432          - scite <unfixed> (embed)          - scite <unfixed> (embed)
433          - qscintilla <unfixed> (embed)          - qscintilla <unfixed> (embed)
434          - qscintilla2 <unfixed> (embed)          - qscintilla2 <unfixed> (embed)
435          - geany <unfixed> (embed)          - geany <unfixed> (fork)
436            - anjuta <unfixed> (embed)
437    
438  libphp-adodb  libphp-adodb
439          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
440          NOTE: also AdoDB-XML Schema          NOTE: also AdoDB-XML Schema
441          - gallery2 <unfixed> (embed)          - gallery2 <unfixed> (embed)
442          - phppgadmin <unfixed> (embed)          - phppgadmin <unfixed> (embed)
443          - egroupware <unfixed> (embed)          - egroupware <unfixed> (embed)
444          - phpwiki <unfixed> (embed)          - phpwiki <unfixed> (embed)
445            - torrentflux 2.0beta1-2 (embed)
446          - ipplan <unfixed> (embed)          - ipplan <unfixed> (embed)
447          - typo3 <unfixed> (embed)          - typo3-src <unfixed> (embed)
         - moodle <unfixed> (embed)  
448          - cacti <unknown> (embed)          - cacti <unknown> (embed)
449          [sarge] - cacti <unfixed> (embed)          [sarge] - cacti <unfixed> (embed)
450          NOTE: dependency exists, but internal version is used          NOTE: dependency exists, but internal version is used
451            - gforge 4.7~rc2-6 (embed)
452            - mahara <unfixed> (embed)
453    
454  gzip  gzip
455          - linux-kernel <unfixed> (embed)          - linux-2.6 <unfixed> (embed) [lib/inflate.c]
         NOTE: lib/inflate.c  
456          - klibc <unfixed> (embed)          - klibc <unfixed> (embed)
457          NOTE: based on linux-kernel gzip code          NOTE: based on linux-kernel gzip code
458          - busybox <unfixed> (embed)          - busybox <unfixed> (embed)
459            - pristine-tar <unfixed> (modified-embed)
460            NOTE: compression code only, not uncompression
461    
462  neon  neon
463          - cadaver <unfixed> (embed; bug #188381)          - cadaver 0.22.3+debian-1 (embed; bug #188381)
464          - gnome-vfs2 <unfixed> (embed; bug #395874)          - gnome-vfs2 <unfixed> (embed; bug #395874)
465          - litmus <unfixed> (embed; #395875)          [etch] - litmus <unfixed> (embed; #395875)
466            - litmus <removed> (embed; #395875)
467          [sarge] - screem <unfixed> (embed)          [sarge] - screem <unfixed> (embed)
468          - sitecopy <unfixed> (embed; bug #395876)          - sitecopy 1:0.16.0-1 (embed; bug #395876)
469          [etch] - tla <unfixed> (embed; bug #395877)          [etch] - tla <unfixed> (embed; bug #395877)
470          [sarge] - tla <unfixed> (embed; bug #395877)          [sarge] - tla <unfixed> (embed; bug #395877)
471    
472  libmodplug  libmodplug
473          - gst-plugins-bad0.10 <unfixed> (embed)          - gst-plugins-bad0.10 0.10.10.2-1 (embed)
474    
475  libvncserver  libvncserver
476          - vino <unfixed> (embed)          - vino <unfixed> (embed)
# Line 322  libvncserver Line 478  libvncserver
478  putty  putty
479          - filezilla <unfixed> (embed)          - filezilla <unfixed> (embed)
480    
481  tinyxml (not packaged in Debian)  tinyxml (not packaged in Debian; itp bug #531968)
482          - filezilla <unfixed>          - filezilla <unfixed>
483            - crystalspace <unfixed> (embed)
484            - libwfut <unfixed> (embed)
485            - rarian <unfixed> (embed)
486            - bulletml <unfixed> (embed)
487            - pokerth <unfixed> (embed)
488            - qutecom <unfixed> (embed)
489            - sofa-framework <unfixed> (embed)
490            - yate <unfixed> (embed)
491            - antigrav <unfixed> (embed)
492            - balder2d <unfixed> (embed)
493            - cal3d <unfixed> (embed)
494            - criticalmass <unfixed> (embed)
495            - ember <unfixed> (embed)
496            - epiphany <unfixed> (embed)
497            - gambit <unfixed> (embed)
498            - noiz2sa <unfixed> (embed)
499            - ogre <unfixed> (embed)
500            - opencity <unfixed> (embed)
501            - openmovieeditor <unfixed> (embed)
502            - pouetchess <unfixed> (embed)
503            - tecnoballz <unfixed> (embed)
504            - trigger-rally <unfixed> (embed)
505            - xmoto <unfixed> (embed)
506            - mapnik <unknown> (embed)
507            NOTE: uses a different XML parser by default
508            - rrootage 0.23a-6 <embed>
509            NOTE: links to libbulltetml
510            - boson <unknown> (embed)
511            NOTE: the embedded code is unused
512    
513  gv  gv
514          - evince <unfixed> (embed)          - evince <unfixed> (embed)
515          NOTE: ps/ tree from gv 3.5.8          NOTE: ps/ tree from gv 3.5.8
516          - evince-gtk <unfixed> (embed)          NOTE: evince-gtk is affected (a component of evince source package)
         NOTE: not packaged in Debian  
517    
518  libXbae  libXbae
519          [etch] - libpawlib2-lesstif <unfixed> (embed)          - paw <removed> (embed)
520          NOTE: from Cernlib          [etch] - paw <unfixed> (embed)
521    
522    libgtkhtml
523            - claws-mail-extra-plugins <unfixed> (fork)
524    
525  libXaw  libXaw
526          [etc] - libpawlib2-lesstif          - paw <removed> (embed)
527          NOTE: from Cernlib          [etch] - paw <unfixed> (embed)
528          NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty          NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
529    
530  libgd2  libgd2
531          - graphviz <unfixed> (embed)          - graphviz <unfixed> (embed)
532          NOTE: lib/gd seems to be 2.0.33          NOTE: lib/gd seems to be 2.0.33
533            - wml 2.0.11ds2-1 (embed)
534            - libwmf <unfixed> (embed)
535            NOTE: derived from gd 1.6.3
536            - texlive-bin 2009-1 (embed)
537    
538  rar  rar
539          - unrar-nonfree <unfixed> (embed)          - unrar-nonfree <unfixed> (embed)
# Line 356  mplayer (DirectMedia Object loader) Line 547  mplayer (DirectMedia Object loader)
547          NOTE: src/libw32dll/          NOTE: src/libw32dll/
548          - vlc <unfixed> (embed)          - vlc <unfixed> (embed)
549          NOTE: modules/codec/dmo/          NOTE: modules/codec/dmo/
550            - mplayer 1.0~rc2-20 (embed)
551    
552  libwpd (WordPerfect converter)  libwpd (WordPerfect converter)
553          - openoffice.org <unfixed> (embed)          - openoffice.org <unfixed> (embed)
# Line 364  fsplib (http://sourceforge.net/projects/ Line 556  fsplib (http://sourceforge.net/projects/
556          - gftp <unfixed> (embed)          - gftp <unfixed> (embed)
557          NOTE: lib/fsplib version 0.3          NOTE: lib/fsplib version 0.3
558    
559    sprng
560            - tree-puzzle <unfixed> (embed)
561    
562  librpcsecgss  librpcsecgss
563          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
564    
565  jasper  jasper
566          - ghostscript <unfixed> (embed)          - ghostscript 8.64~dfsg-2 (embed)
         - gs-gpl <unfixed> (embed)  
567    
568    libiris
569            - psi <unfixed> (embed)
570            - kdenetwork <unfixed> (embed)
571            NOTE: kopete embeds libiris but links dynamically to libidn
572            - kdegames <unfixed> (embed)
573            NOTE: ksirk/kde4
574    
575  libidn  libidn
576          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
577            - psi <unfixed> (embed)
578  liblua          NOTE: psi embeds libiris which embeds libidn
579          - monotone <unfixed> (embed)          - kdegames <unfixed> (embed)
580            NOTE: kdegames/kde4 embeds libiris which embeds libidn
581    
582    lua5.1
583            - monotone 0.43-1 (embed)
584            - nmap 5.00-1 (embed; bug #527997)
585            [lenny] - nmap <unfixed> (embed; bug #527997)
586            - ocropus <unfixed> (embed)
587            - enigma <unfixed> (embed)
588            NOTE: requires lua built with C++
589            - freeciv <unfixed> (embed)
590            - spring <unfixed> (embed)
591    
592  libbotan  libbotan
593          - montone <unfixed> (embed)          - monotone 0.43-1 (embed)
594    
595  NetXX  NetXX
596          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
597    
598  libgc  libgc
599          - mono <unfixed> (embed)          - mono <unfixed> (embed)
600    
601  lzma  lzma
602          - p7zip <unfixed> (embed)          - p7zip <unfixed> (embed)
603            - xz-utils <unfixed> (fork)
604    
605  lzo  lzo
606          - grub2 <unfixed> (embed)          - grub2 <unfixed> (embed)
607    
608    yassl
609            - mysql-dfsg-5.0 <unfixed> (embed)
610            - mysql-dfsg-5.1 <unfixed> (embed)
611    
612  pax code  pax code
613          - tar <unfixed> (embed)          - tar <unfixed> (embed)
614          - cpio <unfixed> (embed)          - cpio <unfixed> (embed)
# Line 399  pax code Line 616  pax code
616  t1lib  t1lib
617          - tetex-bin 2.0.2-1 (embed)          - tetex-bin 2.0.2-1 (embed)
618          - texlive-bin <unknown> (embed)          - texlive-bin <unknown> (embed)
619    
620    guichan
621            - boswars <unfixed> (embed)
622            NOTE: maintainer notified us, working on it
623    
624    tolua
625            - boswars <unfixed> (embed)
626            NOTE: maintainer notified us, working on it
627            NOTE: actually tolua++
628            - ocropus <unfixed> (embed)
629            NOTE: actually tolua++
630            - freeciv <unfixed> (embed)
631            NOTE: actually tolua++
632            - enigma <unfixed> (embed)
633    
634    asio-dev
635            - luxrender <removed> (embed)
636    
637    xine-lib
638            - vlc <unfixed> (embed)
639            NOTE: only parts included in modules/access/rtsp
640    
641    netpbm
642            - tcl8.3 <unfixed> (embed)
643            - tcl8.4 <unfixed> (embed)
644            - tcl8.5 <unfixed> (embed)
645            NOTE: generic/tkImgGIF.c
646    
647    tk8.5
648            - tk8.0 <removed> (old-version)
649            - tk8.3 <unfixed> (old-version)
650            - tk8.4 <unfixed> (old-version)
651            - perl-tk <unfixable> (fork)
652    
653    samba
654            - mc 2:4.6.2~git20080311-1 (embed)
655            NOTE: maintainer is aware of this, currently searching a solution
656    
657    plib1.8.4c2
658            - boson <unfixed> (fork)
659            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
660    
661    fribidi
662            - quesoglc 0.7.2-2 (embed)
663    
664    glew
665            - quesoglc <unfixed> (embed; bug #489341)
666            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
667            - trigger 0.5.2.1-2 (embed)
668            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
669            - trigger-rally 0.5.2.1-2 (embed)
670            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
671    
672    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
673            - transcend <unfixed> (embed)
674            - cultivation <unfixed> (embed)
675            - passage <unfixed> (embed)
676            - gravitation <unfixed> (embed)
677    
678    tar
679            - libarchive <unfixed> (embed)
680            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
681    
682    cpio
683            - libarchive <unfixed> (embed)
684            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
685    
686    kde4libs
687            - kdelibs <unfixable> (old-version)
688    
689    webkit
690            - qt4-x11 <unfixed> (embed; bug #479851)
691            [etch] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
692            - kde4libs <unfixable> (fork)
693            NOTE: kde4lib's khtml and webkit were forked from khtml (this tracking, which seems
694            NOTE: reversed genesis-wise, is used because of so much other stuff in kde4libs)
695    
696    ftgl
697            - blender 2.46+dfsg-1 (embed)
698    
699    wv
700            - abiword <unfixed>
701    
702    qemu
703            - kvm <removed> (embed; bug #543159)
704            - qemu-kvm <unfixed> (embed; bug #560853)
705            NOTE: kvm superceded by qemu-kvm, which is just user interface (no modules)
706            - xen-3 3.4.2-2 (embed; bug #560856)
707            - xen-unstable <unfixed> (embed; bug #560856)
708    
709    vgabios
710            - kvm <removed> (embed; bug #489442)
711            - qemu-kvm <unfixed> (embed)
712    
713    bochs
714            - kvm <removed> (embed; bug #489442)
715            - qemu-kvm <unfixed> (embed)
716    
717    speex
718            - vorbis-tools <unfixed> (embed)
719            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
720            - gst-plugins-good0.10 <unfixed> (embed)
721            - xine-lib <unfixed> (embed)
722            - libfishsound <unfixed> (embed)
723            - libannodex <removed> (embed)
724            - vlc <unfixed> (embed)
725            - xmms-speex <unfixed> (embed)
726            - libsdl-sound1.2 <unfixed> (embed)
727            - sweep <unfixed> (embed)
728    
729    libreadline
730            - magic <itp> (old-version)
731    
732    opcode
733            - ode <unfixed> (embed)
734            NOTE: opcode is not a package in debian, it is just embedded
735            NOTE: http://www.codercorner.com/Opcode.htm
736    
737    gimpact
738            - ode <unfixed> (embed)
739            NOTE: gimpact is not a package in debian, it is just embedded
740            NOTE: http://gimpact.sf.net
741    
742    mochikit
743            - mahara <unfixed> (embed)
744            NOTE: they require extra patches, still unmerged upstream
745            - ntop <unfixed> (embed)
746            - coherence 0.6.2-1 (embed)
747            - paste <unfixed> (embed)
748            - turbogears <unfixed> (embed)
749            - plone3 <removed> (embed)
750            - xulrunner <unfixed> (embed)
751            - libjifty-plugin-chart-perl <unfixed> (embed)
752            - sabnzbdplus <unfixed> (embed)
753            - tgmochikit <unfixed> (embed)
754    
755    prototypejs
756            - netbeans-ide 6.0.1+dfsg-2 (embed)
757            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
758            - webcit <unfixed> (embed; bug #555219)
759            - asterisk 1:1.6.2.0~rc3-1 (embed)
760            - libjson-ruby 1.1.4-1 (embed; bug #555224)
761            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
762            - horde3 <unfixed> (embed)
763            - knowledgeroot 0.9.9.5-1 (embed; bug #555230)
764            - mediatomb 0.12.0~svn2018-5 (embed; bug #555233)
765            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
766            - ebug-http <removed> (embed; bug #555236)
767            - libaws 2.7-1 (embed; bug #555222)
768            - phpgedview <removed> (embed)
769            - poker-network 1.7.6-1 (embed; bug #555238)
770            - rails 2.1.0-6 (embed)
771            - wordpress 2.5.0-2 (embed; bug #555243)
772            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
773            TODO: search through all of the other zope packages
774            - ampache 3.4.1-2 (embed)
775            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
776            - hobix 0.5~svn20070319-4 (embed; bug #555247)
777            - zabbix 1.6.6-4 (embed; bug #555250)
778            - chora2 <unfixed> (embed; bug #555253)
779            - gollem <unfixed> (embed; bug # 555254)
780            - jscropperui 1.2.1-1 (embed; bug #555257)
781            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
782            - ingo1 1.2.3+debian0-1 (embed; bug #555261)
783            - kronolith2 2.3.3+debian0-1 (embed; bug #555262)
784            - activeldap <unfixed> (embed)
785            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
786            - mantis 1.1.2+dfsg-1 (embed; bug #555265)
787            - otrs2 2.3.4-6 (embed; bug #555267)
788            - webcalendar 1.2~b1-2 (embed; bug #555269)
789            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
790            - jifty 0.90519-1 (embed; bug #555271)
791            - jquery 1.4-1 (embed; bug #555272)
792            - passenger 2.2.5debian1-1 (embed; bug #555273)
793            - plone3 <removed> (embed; bug #555275)
794            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
795            - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
796            - xulrunner <unfixed> (embed)
797            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
798    
799    gdb
800            - insight <unfixed> (embed)
801    
802    e2fsprogs
803            - ldiskfsprogs <unfixable> (fork)
804    
805    quazip (not packaged in Debian)
806            - qcake <unfixed> (embed)
807            NOTE: starting with upstream version 0.6.4
808    
809    exo
810            - pcmanfm <unfixed> (embed; bug #499677)
811            NOTE: slightly modified source code
812    
813    java
814            - openjdk-6 <unfixed>
815            - sun-java5 <unfixed>
816            - sun-java6 <unfixed>
817    
818    libphp-snoopy
819            - ampache 3.4.1-2 (embed; bug #504169)
820            - gforge 4.6.99+svn6094-2 (embed)
821            - mahara 1.0.5-2 (embed; bug #504170)
822            - pixelpost 1.7.1-5 (embed; bug #504171)
823            - mediamate 0.9.3.6-5 (embed; bug #504172)
824            - opendb <removed> (embed; bug #504173)
825            [etch] - opendb <unfixed> (embed; bug #504173)
826            - wordpress 2.5.1-9 (embed; bug #443948)
827            - moodle <unfixed> (embed; bug #507185)
828            [etch] - phpgroupware <unfixed> (embed)
829            NOTE: phpgroupware-felamimail
830            - magpierss 0.72-3 (embed; bug #431089)
831    
832    jquery
833            - zekr <unfixed> (embed)
834            - wordpress <unknown> (embed)
835            - yocto-reader <unfixed> (embed)
836            - textpattern <unfixed> (embed)
837            - genshi 0.5.1-1 (embed)
838            NOTE: compressed file under examples/ dir
839            - prewikka <unfixed> (embed)
840            - libramaze-ruby <unfixed> (embed)
841            - drupal5 <unfixed> (embed)
842            - b2evolution <unfixed> (embed)
843            - wesnoth <unfixed> (embed)
844    
845    tablesorter (jquery plugin, not packaged yet)
846            - wesnoth <unfixed> (embed)
847    
848    kses
849            - wordpress <unfixed> (embed; bug #504242)
850            NOTE: their copy has all methods renamed to wp_<foo>
851            NOTE: kses isn't in Debian, RFP: #504240
852            - moodle <unfixed> (embed; bug #507185)
853            - egroupware <unfixed> (embed)
854    
855    magpierss
856            - wordpress <unfixed> (embed; bug #504242)
857            - moodle <unfixed>
858    
859    php-gettext
860            - wordpress 2.8.4-1 (embed; bug #504242)
861            - docbookwiki <unfixed> (embed)
862            - knowledgeroot 0.9.9.5-1
863            NOTE: non-free
864    
865    libphp-ixr (name may change, it is the Incutio XML-RPC)
866            - wordpress <unfixed> (embed; bug #504242)
867            NOTE: libphp-ixr isn't in Debian, RFP: #504236
868            - dokuwiki <unfixed> (embed)
869            - textpattern <unfixed> (embed)
870    
871    libphp-cas
872            - glpi <unfixed> (embed)
873            - moodle <unfixed> (embed; bug #505984)
874    
875    scriptaculous (prototype.js is among the embeds in the following)
876            - glpi <unfixed> (embed)
877            - libaws <unfixed> (embed; bug #555222)
878            - op-panel <unfixed> (embed)
879            - symfony <unfixed> (embed)
880            NOTE: maintainer says there are extra incompatible changes required
881            - pixelpost 1.7.1-6 (embed)
882            - webhelpers <unfixed> (embed)
883            - qwik <removed> (embed; bug #555241)
884            - smokeping <unfixed> (embed)
885            - turba2 <unfixed> (embed)
886            - typo3-src 4.2.3-1 (embed)
887            - request-tracker3.6 <unfixed> (embed)
888            - request-tracker3.8 <unfixed> (embed)
889            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
890            - wordpress 2.5.0-2 (embed)
891            - libhtml-prototype-perl 1.48-3 (embed)
892    
893    libmarkdown-php
894            - moodle <unfixed> (embed; bug #507185)
895            - pixelpost 1.7.1-6 (embed)
896    
897    php-openid
898            - wordpress-openid <itp> (embed)
899    
900    geshi
901            - dokuwiki 0.0.20080505-3.1 (embed)
902            - pgfouine 1.0-1.1 (embed)
903            - websvn 2.1.0-1 (embed)
904    
905    webcalendar
906            - gforge 4.7~rc2-6 (embed; bug #504758)
907    
908    libical
909            - kdepim <unknown> (fork)
910            NOTE: fixed at some point during 4.0
911            - kdepimlibs 4.2.0-1 (fork)
912            - claws-mail-extra-plugins <unfixed> (fork)
913    
914    harfbuzz
915            - qt4-x11 <unfixed> (embed)
916            - pango1.0 <unfixed> (embed)
917            - fontmatrix <unfixed> (embed)
918    
919    libzip
920            - php5 <unfixable> (modified-embed)
921            - odt2txt <unfixed> (embed; bug #523808)
922    
923    json.php (not packaged; should be replaced with php's built-in functions)
924            - moodle <unfixed>
925            - yui <unfixed>
926            - gallery2 <unfixed>
927            - dokuwiki <unfixed>
928            - typo3-src <unfixed>
929    
930    php-fpdf
931            - tcpdf <itp> (fork)
932            - moodle <unfixed>
933            - phpwiki <unfixed>
934            - egroupware <unfixed>
935            - ldap-account-manager <unfixed> (fork)
936    
937    tcpdf (itp: #495985)
938            - moodle <unfixed>
939            - phpmyadmin <unfixed>
940    
941    typo3
942            - moodle <unfixed>
943    
944    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
945            - moodle <unfixed>
946            - gosa <unfixed>
947    
948    php-ole (itp: #487558)
949            - moodle <unfixed>
950    
951    pieforms (http://www.catalyst.net.nz)
952            - mahara <unfixed>
953    
954    savant2 (http://phpsavant.com)
955            - egroupware <unfixed>
956    
957    rssparser (http://nwow.org)
958            - egroupware <unfixed>
959            - phpgroupware <unfixed>
960    
961    lcms
962            - openjdk-6 <unfixed> (fork)
963            - gimp 2.4.0~rc2-2
964    
965    libphp-phplayersmenu
966            - diogenes <unfixed>
967            - phpldapadmin <unfixed>
968    
969    libphp-pclzip
970            - docvert <unfixed>
971            - moodle <unfixed>
972            - egroupware <unfixed>
973    
974    libphp-simplepie
975            - dokuwiki <unfixed>
976            - wordpress <unfixed>
977    
978    libphp-jpgraph
979            - egroupware <unfixed>
980    
981    php-simpletest
982            - moodle <unfixed>
983    
984    libpng
985            - iceweasel <not-affected> (uses xulrunner)
986            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
987            - iceape 1.0.13~pre080614i-0etch1 (embed)
988            - xulrunner 1.9.0.13-1 (embed)
989            [lenny] - xulrunner 1.9.0.11-0lenny1
990            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
991            - gamera 3.2.3-1 (embed)
992            - freeimage <unfixed> (embed)
993            - tuxonice-userui (static)
994    
995    irssi
996            - silc-client <unfixed> (embed)
997            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
998    
999    extc
1000            - mtasc <unfixed> (embed)
1001            - haxe <unfixed> (embed)
1002    
1003    swflib
1004            - mtasc <unfixed> (embed)
1005            - haxe <unfixed> (embed)
1006    
1007    libitext-java
1008            - bouncycastle 2.1.4-1 (embed)
1009    
1010    python-ply
1011            - pyke <unfixed> (embed; bug #555363)
1012            - pywbem 0.7.0-4 (embed; bug #555364)
1013            - sepolgen <unfixed> (embed; bug #555365)
1014            - zope-textindexng3 <unknown> (embed)
1015            - iceweasel <not-affected> (uses xulrunner)
1016            - xulrunner <unknown> (embed)
1017            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
1018    
1019    libdumbnet (libdnet upstream)
1020            - nmap <unfixed> (fork)
1021    
1022    gcc-4.4
1023            - gcc-mingw32 <unfixed> (embed)
1024    
1025    camlimages
1026            - advi <unfixed> (static; bug #550441)
1027    
1028    memcached
1029            - memcachedb <unfixed> (embed)
1030    
1031    yajl
1032            - argyll <unfixed> (embed; bug #544223)
1033            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
1034    
1035    nusoap
1036            - gforge 4.8.2-1 (embed)
1037            - ampache <unfixed> (embed)
1038            - poker-network <unfixed> (embed)
1039            - moodle <unfixed> (embed)
1040            NOTE: code is not used when running under php5 and soap is enabled
1041            - phpwiki <unfixed> (embed)
1042            - gallery2 <unfixed> (embed)
1043            - typo3-src <unfixed> (embed)
1044    
1045    libept
1046            - adept <unfixed> (embed; bug #540649)
1047    
1048    libvorbis
1049            - iceweasel <not-affected> (uses xulrunner)
1050            - xulrunner <unfixed> (embed; bug #540959)
1051            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1052            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1053            - iceape <unfixed> (embed)
1054            [etch] - iceape <not-affected> (introduced in 2.0)
1055            [lenny] - iceape <not-affected> (introduced in 2.0)
1056    
1057    cairo
1058            - iceweasel <not-affected> (uses xulrunner)
1059            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1060    
1061    liboggz
1062            - iceweasel <not-affected> (uses xulrunner)
1063            - xulrunner <unfixed> (embed; bug #540959)
1064            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1065            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1066            - iceape <unfixed> (embed)
1067            [etch] - iceape <not-affected> (introduced in 2.0)
1068            [lenny] - iceape <not-affected> (introduced in 2.0)
1069    
1070    liboggplay
1071            - iceweasel <not-affected> (uses xulrunner)
1072            - xulrunner <unfixed> (embed; bug #540959)
1073            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1074            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1075            - iceape <unfixed> (embed)
1076            [etch] - iceape <not-affected> (introduced in 2.0)
1077            [lenny] - iceape <not-affected> (introduced in 2.0)
1078    
1079    php-net-dnsbl
1080            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1081    
1082    php-onyx-rss
1083            - serendipity <unfixed> (embed; bug #541740; wontfix: only one script, own package is overkill, appears not to be duplicated in Debian)
1084    
1085    php-text-wiki
1086            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1087    
1088    php-xml-rpc
1089            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1090    
1091    polarssl (does not have a shared library)
1092            - pdkim <itp> (embed; bug #543150)
1093            - xyssl <unfixed> (old-version)
1094    
1095    pidgin (libpurple)
1096            - gaim <removed> (old-version)
1097            - qutecom 2.2~rc3.hg396~dfsg1-6 (embed; bug #559785)
1098    
1099    icu
1100            - webkit 1.0.1-1 (embed; bug #547214)
1101            - texlive-bin <unfixed> (fork)
1102            NOTE: texlive upstream working with icu upstream to merge their changes
1103    
1104    cyrus-imapd-2.2
1105            - kolab-cyrus-imapd <unfixed> (fork)
1106            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1107    
1108    python-cxx-dev
1109            - freecad 0.9.2646.3-1 (embed; bug #547936)
1110    
1111    zipios++
1112            - freecad 0.9.2646.3-1 (embed; bug #547941)
1113            - enigma 0.92.3-3 (embed)
1114            NOTE: likely fixed earlier, marking etch's version as fixed
1115    
1116    linux-2.6
1117            - kvm <removed> (embed; bug #549973) [./kernel/*]
1118            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1119            - kernel-source-2.6.8 <removed> (old-version)
1120            - kernel-source-2.4.27 <removed> (old-version)
1121            - kernel-source-2.4.24 <removed> (old-version)
1122            - kernel-source-2.2.25 <removed> (old-version)
1123            - kernel-source-2.2.20 <removed> (old-version)
1124    
1125    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1126            - kvm <removed> (embed) [./libfdt/*]
1127            - qemu-kvm <unfixed> (embed) [./libfdt/*]
1128    
1129    qweb (not packaged)
1130            - ajaxterm <unfixed>
1131    
1132    opensaml2
1133            - opensaml <removed> (old-version)
1134    
1135    shibboleth-sp2
1136            - shibboleth-sp <removed> (old-version)
1137    
1138    tuxonice-userui
1139            - suspend2-userui <removed> (old-version)
1140    
1141    expat
1142            - w3c-libwww <removed> (embed; bug #551941)
1143            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1144            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1145            - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1146            - python2.4 <unfixable> (embed; bug #553403)
1147            - python-4suite <unfixed> (embed; bug #516935)
1148            - wxwindows2.4 <removed> (embed)
1149            - wxwidgets2.6 2.6.3.2.2-4 (embed)
1150            - wxwidgets2.8 2.8.10.1-2 (embed)
1151            - celementtree 1.0.5-8 (embed)
1152            NOTE: Maybe that was fixed even earlier
1153            - audacity 1.3.2-1 (embed)
1154            - matanza <unfixed> (embed)
1155            - tdom 0.8.3~20080525-1 (embed)
1156            - udunits 2.1.8-4 (embed)
1157            - apr-util 1.2 (embed)
1158            - ayttm <unfxed> (embed; bug #561006)
1159            - cableswig <unfixed> (embed)
1160            - cadaver <unfixed> (embed)
1161            - cmake 2.6.0-6 (embed)
1162            - coin3 <unfixed> (embed)
1163            - gdcm 2.0.14-2 (embed)
1164            - ghostscript 8.71~dfsg-2 (embed)
1165            - grmonitor <removed> (embed)
1166            - iceape <unfixed> (embed)
1167            - insighttoolkit 3.16.0-1 (embed)
1168            NOTE: insighttoolkit might've been fixed earlier
1169            - libparagui1.1 1.0.2-1 (embed)
1170            - paraview 3.6.2-1 (embed)
1171            - poco 1.3.6p1-1 (embed)
1172            - simgear <unfixed> (embed)
1173            - sitecopy 1:0.16.0-1
1174            - smart <unfixed> (embed)
1175            NOTE: smart embeds celementree, and it includes expat
1176            - swish-e <not-affected> (Linked against libxml, which is used instead)
1177            - tla 1.3.5+dfsg-15 (embed)
1178            - vtk 4.1.20030227-1 (embed)
1179            - wbxml2 <not-affected> (expat code is only used on Mac OS X, see #560941)
1180            - xmlrpc-c <unfixed> (embed)
1181            - iceweasel <unfixed> (embed)
1182            - kompozer <unfixed> (embed)
1183            - vxl 1.13.0-2 (embed)
1184            - xulrunner <unfixed> (embed)
1185            - apache2 2.2 (embed)
1186            - texlive-bin <not-affected> (Embedded code not compiled in)
1187            - vnc4 <unfixed> (embed)
1188            - xotcl 1.6.6-1 (embed)
1189    
1190    xerces-c
1191            - xerces-c2 <unfixed> (old-version)
1192            - xerces27 <removed> (old-version)
1193    
1194    md5 (RSA's version; not the gnu version provided by coreutils)
1195            - w3c-libwww <removed> (embed; bug #551942)
1196            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1197    
1198    libparagui1.1
1199            - asc <unfixable> (fork)
1200    
1201    enet
1202            - sauerbraten <unfixed> (embed; #497194)
1203    
1204    eglibc
1205            - glibc <removed> (old-version)
1206    
1207    galib
1208            - gamera 3.2.3-1 (embed)
1209    
1210    configobj
1211            - bzr 2.1.0~rc2-1 (embed; bug #555336)
1212            - elisa <unfixed> (embed; bug #555337)
1213            - gaupol <unfixed> (embed; bug #555338)
1214            - ipython <unfixed> (embed; bug #555339)
1215            - pida <unfixed> (embed; bug #555340)
1216            - psychopy <unfixed> (embed; bug #555341)
1217            - rest2web <unfixed> (embed; bug #555342)
1218            - auth2db <unknown> (embed)
1219            - dynagen <unknown> (embed)
1220            - iceweasel <unknown> (embed)
1221            - sabnzbdplus <unknown> (embed)
1222            - xulrunner <unknown> (embed)
1223            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1224    
1225    python-clientform
1226            - bibus <unfixed> (embed; bug #555332)
1227            - zope2.10 <unfixed> (embed; bug #555333)
1228            - zope2.11 <removed> (embed; bug #555334)
1229            - python-mechanize <unknown> (embed)
1230            - twill <unknown> (embed)
1231    
1232    python-mechanize
1233            - zope2.10 <unfixed> (embed; bug #555337)
1234            - zope2.11 <removed> (embed; bug #555338)
1235            - twill <unknown> (embed; bug #555339)
1236    
1237    pexpect
1238            - duplicity 0.6.06-1 (embed; bug #555361)
1239            - hplip <unfixed> (embed; bug #555362)
1240            - smart <unfixed> (embed; bug #555363)
1241    
1242    pyparsing
1243            - bauble <unfixed> (embed; bug #555366)
1244            - boa-constructor 0.6.1-8 (embed; bug #555367)
1245            - calibre <unfixed> (embed; bug #555368)
1246            - matplotlib <unfixed> (embed; bug #531024)
1247            - zhpy 1.7.3.1-1 (embed; bug #555370)
1248            - polybori <unknown> (embed)
1249            - python-whoosh <unknown> (embed)
1250            - twill <unknown> (embed)
1251            - zope-textindexng3 <unknown> (embed)
1252    
1253    python-pysqlite2
1254            - python2.4 <unfixed> (embed; bug #553403)
1255            - python2.5 <unfixed> (embed; bug #553403)
1256    
1257    celementtree
1258            - python2.5 <unfixed> (embed)
1259            - smart <unfixed> (embed)
1260    
1261    elementtree
1262            - python2.5 <unfixed> (embed)
1263            - python2.6 <unfixed> (embed)
1264            - bzr 2.1.0~rc2-1 (embed; bug #555343)
1265            - gedit 2.28.2-1 (embed; bug #555344)
1266            - smart <unfixed> (embed)
1267            - solfege <unfixed> (embed; bug #555345)
1268            - w3af <unfixed> (embed; bug #555346)
1269            - python-qt4 <unknown> (embed)
1270            - sphinx <unknown> (embed)
1271            - python-nltk <itp> (embed)
1272    
1273    python2.5
1274            - python2.4 <unfixed> (old-version)
1275            - jython <unfixed> (embed)
1276            NOTE: embeds many stdlib modules
1277            - python-django <unfixed> (embed; bug #555419)
1278            NOTE: embeds stdlib modules: doctest, decimal
1279            - gamera 3.2.3-1 (embed)
1280            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1281            - boa-constructor <unfixed> (embed; bug #555426)
1282            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1283            - nicotine <unfixed> (embed; bug #555427)
1284            NOTE: embeds stdlib modules: ConfigParser
1285            - museek+ <unfixed> (embed; bug #555428)
1286            NOTE: embeds stdlib modules: ConfigParser
1287            - vegastrike-data <unfixed> (embed)
1288            NOTE: embeds many stdlib modules
1289            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1290            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1291            - config-manager <unfixed> (embed; bug #555423)
1292            NOTE: embeds stdlib modules: optparse
1293            - jhbuild 2.28.0-1 (embed; bug #555421)
1294            NOTE: embeds stdlib modules: optparse, subprocess
1295            - smart <unfixed> (embed; bug #555432)
1296            NOTE: embeds stdlib modules: optparse
1297            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1298            NOTE: embeds stdlib modules: doctest
1299            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1300            NOTE: embeds stdlib modules: doctest
1301            - distribute <unfixed> (embed)
1302            NOTE: embeds stdlib modules: doctest
1303            - python-setuptools <unfixed> (embed; bug #555435)
1304            NOTE: embeds stdlib modules: doctest
1305            - zope.testing <unfixed> (embed; bug #555436)
1306            NOTE: embeds stdlib modules: doctest
1307            - translate-toolkit <unfixed> (embed; bug #555422)
1308            NOTE: embeds stdlib modules: textwrap, contextlib
1309            - libtpclient-py <unfixed> (embed; bug #555424)
1310            NOTE: embeds stdlib modules: subprocess
1311            - grass <unfixed> (embed; bug #555425)
1312            NOTE: embeds stdlib modules: subprocess
1313            - coherence <unfixed> (embed; bug #555429)
1314            NOTE: embeds stdlib modules: uuid
1315            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1316            NOTE: embeds stdlib modules: uuid
1317            - setroubleshoot <unfixed> (embed; bug #555431)
1318            NOTE: embeds stdlib modules: uuid
1319            - linkchecker <unfixed> (embed; bug #555414)
1320            NOTE: embeds msgfmt.py script
1321            - imdbpy <unfixed> (embed)
1322            NOTE: embeds msgfmt.py script
1323            - kiwi <unfixed> (embed)
1324            NOTE: embeds msgfmt.py script
1325            - moin <unfixed> (embed)
1326            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1327            - plone3 <removed> (embed)
1328            NOTE: embeds msgfmt.py script
1329            - roundup <unfixed> (embed)
1330            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1331            - rednotebook <unfixed> (embed; bug #555415)
1332            NOTE: embeds msgfmt.py script
1333            - turbogears <unfixed> (embed)
1334            NOTE: embeds msgfmt.py script
1335            - elisa <unfixed> (embed)
1336            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1337            - calibre <unfixed> (embed)
1338            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1339            - mailman 1:2.1.13-1 (embed; #555416)
1340            NOTE: embeds msgfmt.py script
1341            - python-docutils <unknown> (embed)
1342            NOTE: embeds stdlib modules: optparse, textwrap
1343            - python-imaging <unknown> (embed)
1344            NOTE: embeds stdlib modules: doctest
1345            - python-mechanize <unknown> (embed)
1346            NOTE: embeds stdlib modules: doctest
1347            - twill <unknown> (embed)
1348            NOTE: embeds stdlib modules: subprocess
1349            - zeroc-ice <unknown> (embed)
1350            NOTE: embeds stdlib modules: subprocess
1351            - wxwidgets2.8 <unknown> (embed)
1352            NOTE: embeds stdlib modules: subprocess
1353            - cycle <unknown> (embed)
1354            NOTE: embeds msgfmt.py script
1355            - deluge <unknown> (embed)
1356            NOTE: embeds msgfmt.py script
1357            - opendict <unknown> (embed)
1358            NOTE: embeds msgfmt.py script
1359            - openerp-client <unknown> (embed)
1360            NOTE: embeds msgfmt.py script
1361            - rapidsvn <unknown> (embed)
1362            NOTE: embeds msgfmt.py script
1363            - wammu <unknown> (embed)
1364            NOTE: embeds msgfmt.py script
1365            - gaphor <unknown> (embed)
1366            NOTE: embeds msgfmt.py script
1367            - pida <unknown> (embed)
1368            NOTE: embeds msgfmt.py script
1369            - python-formencode <unknown> (embed)
1370            NOTE: embeds msgfmt.py script
1371            - duplicity <unfixed> (embed)
1372            NOTE: embeds stdlib module: urlparse, tarfile
1373            - pygopherd <unfixed> (embed)
1374            NOTE: embeds stdlib module: zipfile
1375    
1376    argparse
1377            - twill <unfixed> (embed; bug #555347)
1378            - ipython <unfixed> (embed; bug #555348)
1379    
1380    coherence
1381            - elisa <unfixed> (embed; bug #555335)
1382    
1383    simpletal
1384            - plastex <unfixed> (embed; bug #555371)
1385    
1386    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1387            - postr <unfixed> (embed)
1388            - elisa <unfixed> (embed)
1389    
1390    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1391            - apertium-tolk <unfixed> (embed)
1392            - ipython <unfixed> (embed)
1393            - virtaal <unfixed> (embed)
1394    
1395    distribute
1396            - setuptools <removed> (old-version)
1397    
1398    rails
1399            - jruby1.2 <unfixed> (embed) [./bench/rails/*]
1400            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1401            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1402            - thin <unfixed> (embed) [./spec/rails_app/*]
1403            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1404            NOTE: be dangerous if developers are naively basing their code off of the examples
1405            NOTE: prototype.js is among the example files
1406    
1407    lucene2 (prototype.js is among the embeds in the following)
1408            - lucene <unfixed> (old-version)
1409            - pylucene <unfixed> (embed)
1410            - libpdfbox-java <unfixed> (embed)
1411            - libfontbox-java <unfixed> (embed)
1412            - libjempbox-java <unfixed> (embed)
1413            - solr <unfixed> (embed)
1414    
1415    unicode-data
1416            - syslinux <unfixed> (embed)
1417            - camomile <unfixed> (embed)
1418            - fribidi <unfixed> (embed)
1419            - m17n-db <unfixed> (embed)
1420            - sbcl <unfixed> (embed)
1421            - heimdal <unfixed> (embed)
1422            - icu <unfixed> (embed)
1423            - icu4j <unfixed> (embed)
1424            - krb5 <unfixed> (embed)
1425            - moodle <unfixed> (embed)
1426            - openldap <unfixed> (embed)
1427            - pike7.6 <unfixed> (embed)
1428            - samba <unfixed> (embed)
1429            - samba4 <unfixed> (embed)
1430            - cmucl <unfixed> (embed)
1431            - typo3-src <unfixed> (embed)
1432            - mauve <unfixed> (embed)
1433            - texlive-bin <unfixed> (embed)
1434            - ypsilon <unfixed> (embed)
1435            - jeuclid <unfixed> (embed)
1436            - charmap.app <unfixed> (embed)
1437            - clisp <unfixed> (embed)
1438            - gnulib <unfixed> (embed)
1439            - opensrs-client <unfixed> (embed)
1440            - saxonb <unfixed> (embed)
1441            - rails <unfixed> (embed)
1442    
1443    feedparser
1444            - rawdog <unfixed> (embed; bug #383422)
1445            - miro <unfixed> (embed; bug #555351)
1446            - calibre <unfixed> (embed; bug #555352)
1447            - freevo <unfixed> (embed; bug #555353)
1448            - pida <unfixed> (embed; bug #555354)
1449            - planet-venus <unfixed> (embed; bug #555355)
1450            - plone3 <removed> (embed; bug #555356)
1451            - exaile 0.2.14+debian-1 (embed)
1452            - screenlets 0.1.2-3 (embed)
1453            NOTE: included twice
1454    
1455    agg:
1456            - matplotlib <unfixed> (embed: bug #377271)
1457            - contextfree <unfixed> (embed)
1458            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1459            - exactimage <unfixed> (embed)
1460            - python-enable <unfixed> (embed)
1461            - mapnik 0.5.1-3 (embed)
1462            NOTE: links statically to agg, but shared library is not available (bug #377271)
1463    
1464    vtk
1465            - paraview <unfixable> (embed; bug #495426)
1466    
1467    txt2tags
1468            - rednotebook <unfixed> (embed)
1469    
1470    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1471            - gajim <unfixed> (embed)
1472            - emesene <unfixed> (embed)
1473            - convirt <unfixed> (embed)
1474            - pida <unfixed> (embed)
1475            - rednotebook <unfixed> (embed)
1476    
1477    horde3 (prototype.js is among the embeds in the following)
1478            - mnemo2 <unfixed> (embed)
1479            - nag2 <unfixed> (embed)
1480            - wordpress <unfixed> (embed)
1481            NOTE: Text_Diff (wp-includes/Text/Diff*)
1482    
1483    cimg
1484            - gmic <itp> (embed)
1485    
1486    mootools
1487            - gmic <itp> (embed)
1488    
1489    openldap
1490            - openldap2.3 <removed> (old-version)
1491    
1492    grub2
1493            - grub <unfixed> (old-version)
1494    
1495    gnupginterface
1496            - duplicity <unfixed> (embed)
1497    
1498    python-dateutil
1499            - awn-extras-applets <unfixed> (embed)
1500            - matplotlib <unknown> (embed)
1501    
1502    cups
1503            - cupsys <removed> (old-version)
1504    
1505    yui
1506            - bcfg2 <not-affected> (present in source but not included in any binary files)
1507            - serendipity 1.5.3-1 (embed; bug #557746)
1508            - moodle 1.8.2.dfsg-5 (embed)
1509            - jifty 0.91117-1 (embed; bug #557748)
1510            - webgui 7.7.26-1 (embed)
1511            - loggerhead 1.17-1 (embed)
1512    
1513    quake3 (vanilla source not packaged in debian)
1514            - openarena <unfixable> (fork)
1515    
1516    quake2 (vanilla source not packaged in debian)
1517            - alien-arena <unfixable> (fork)
1518            - warsow <unfixable> (fork)
1519    
1520    libtheora
1521            - iceweasel <not-affected> (uses xulrunner)
1522            - xulrunner <unfixed> (embed; bug #540959)
1523            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1524            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1525            - iceape <unfixed> (embed; bug #559276)
1526            [etch] - iceape <not-affected> (introduced in iceape 2.0)
1527            [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1528    
1529    dtoa
1530            - bfilter <unfixed> (embed)
1531            - cacao <unfixed> (embed)
1532            - cdrdao <unfixed> (embed)
1533            - classpath <unfixed> (embed)
1534            - freej <unfixed> (embed)
1535            - iceape <unfixed> (embed)
1536            - iceweasel <unfixed> (embed)
1537            - jscoverage <unfixed> (embed)
1538            - kde4libs <unfixed> (embed)
1539            - kdelibs <unfixed> (embed)
1540            - kompozer <unfixed> (embed)
1541            - libv8 <unfixed> (embed)
1542            - mono <unfixed> (embed)
1543            - newlib <unfixed> (embed)
1544            - nspr <unfixed> (embed)
1545            - php5 <unfixed> (embed)
1546            - polyml <unfixed> (embed)
1547            - qt4-x11 <unfixed> (embed)
1548            - rhino <unfixed> (embed)
1549            NOTE: code translated to Java
1550            - ruby1.8 <unfixed> (embed)
1551            - ruby1.9 <unfixed> (embed)
1552            - ruby1.9.1 <unfixed> (embed)
1553            - sdd <unfixed> (embed)
1554            - sfind <unfixed> (embed)
1555            - star <unfixed> (embed)
1556            - tinymux <unfixed> (embed)
1557            - virtualbox-ose <unfixed> (embed)
1558            - webkit <unfixed> (embed)
1559            - xulrunner <unfixed> (embed)
1560    
1561    ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1562            - firegpg <unfixed> (embed)
1563            - enigmail <unfixed> (embed)
1564    
1565    ptmalloc (not packaged in Debian)
1566            - crystalspace <unfixed> (embed)
1567            - qt4-x11 <unfixed> (embed)
1568    
1569    svgalib
1570            - usplash <unfixed> (embed)
1571    
1572    bogl
1573            - usplash <unfixed> (embed)
1574    
1575    taglist
1576            - usplash <unfixed> (embed)
1577    
1578    portaudio
1579            - audacity <unfixed> (embed; bug #323711)
1580    
1581    nyquist
1582            - audacity <unfixed> (embed)
1583            NOTE: embeds a forked nyquist with support for a shared library
1584    
1585    vamp-plugin-sdk
1586            - audacity <unfixed> (embed)
1587    
1588    wordpress
1589            - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1590            - wordpress-mu <removed> (fork)
1591    
1592    php5
1593            - php4 <removed> (old-version)
1594    
1595    classpath
1596            - libgnucrypto-java <removed> (embed; bug #559788)
1597    
1598    libtool
1599            - apr <unfixed> (static; bug #489625)
1600            NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1601            - arts <unfixed> (embed)
1602            - bochs 2.4.2-1 (embed; bug #560884)
1603            - camserv <unfixed> (embed)
1604            - collectd 4.8.2-1 (embed)
1605            - courier-authlib 0.58-4 (embed)
1606            NOTE: The etch version of courier-authlib was the earliest version checked, might be fixed earlier
1607            - cvsnt 2.5.04.3236-1.2 (embed)
1608            - dico <not-affected> (Uses the system copy of ltdl)
1609            - freeradius 0.1+20010527-1 (embed)
1610            NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1611            - ggobi 2.1.9~20091212-1 (embed)
1612            - glame 2.0.1-4 (embed)
1613            NOTE: The etch version of glame was the earliest version checked, might be fixed earlier
1614            - gnash 0.8.7-2 (embed)
1615            - gnu-smalltalk <unfixed> (embed; bug #566777)
1616            - google-gadgets 0.10.5-0.3 (embed)
1617            NOTE: 0.10.5-0.3 was the earliest version checked, was fixed earlier
1618            - graphicsmagick 1.3.5-6 (embed)
1619            - graphviz 2.8-3 (embed)
1620            NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1621            - guile-1.6 1.6.8-7 (embed)
1622            - hamlib <unfixed> (embed)
1623            - hercules 3.06-1.2 (embed)
1624            - jags 1.0.4-3 (embed; bug #560864)
1625            - kdelibs <unfixed> (embed)
1626            - libannodex <removed> (embed)
1627            - libextractor 0.5.23+dfsg-4 (embed)
1628            - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1629            - libtunepimp 0.5.3-7.3 (embed)
1630            - mp4h 1.3.1-4.1 (embed)
1631            - naim <removed> (embed)
1632            - parser-mysql <unfixed> (embed)
1633            - pinball 0.3.1-11 (embed)
1634            - redland <unfixed> (embed)
1635            - siproxd <unfixed> (embed)
1636            - ski <unfixed> (embed)
1637            - synfig 0.62.00-1 (embed)
1638            - unixodbc 2.2.4-5 (embed)
1639            - xmlsec1 <not-affected> (Doesn't enable dynamic loading of crypto modules)
1640            - clamav 0.95+dfsg-1 (embed)
1641            - imagemagick 6:6.2.3.1-1 (embed)
1642            - hypre 2.4.0b-5 (embed)
1643            - lam <unfixed> (embed)
1644            - openmpi <unfixable> (embed; bug #559386)
1645            - parser <unfixed> (embed)
1646            - pdsh 2.18-5 (embed; bug #560892)
1647            - sbnc 1.2-8 (embed)
1648            - sdcc <unfixed> (embed)
1649            - wml <not-affected> (The embedded ltdl isn't used, instead mp4h is used, see 559841)
1650            - proftpd-dfsg <unfixed> (embed; bug #561748)
1651            - babel 1.4.0.dfsg-5 (embed)
1652            - libprelude 0.9.14-2 (embed)
1653            - heartbeat 2.1.4-7 (embed)
1654            NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1655            NOTE: might've been fixed earlier
1656            - gcc-* <unknown> (embed)
1657    
1658    ocamlgsl
1659            - orpie 1.5.1-7.1 (embed; bug #550058)
1660    
1661    xdotool
1662            - keynav <unfixed> (embed; bug #560103)
1663    
1664    bulletphysics (not packaged; http://www.bulletphysics.org/)
1665            - supertuxkart <unfixed> (embed)
1666            - blender <unfixed> (embed)
1667    
1668    ghostscript
1669            - gs-gpl <removed> (old-version)
1670    
1671    icedove
1672            - thunderbird <removed> (old-version)
1673    
1674    sizzlejs (not packaged in Debian, http://sizzlejs.com/)
1675            - jquery <unfixed> (embed)
1676    
1677    sed
1678            - ssed <unfixed> (fork)
1679    
1680    phpatomlib (http://code.google.com/p/phpatomlib)
1681            - wordpress <unfixed> (embed)
1682    
1683    Services_JSON (http://pear.php.net/package/Services_JSON)
1684            - wordpress <unfixed> (embed)
1685    
1686    phpass (http://www.openwall.com/phpass/)
1687            - gallery2 <unfixed> (embed)
1688            - wordpress <unfixed> (embed)
1689            - typo3-src <unfixed> (modified-embed)
1690            NOTE: file refers to drupal, maybe there's a copy somewhere there
1691            NOTE: a copyright owner search didn't match anything
1692            - libauthen-passphrase-perl <unfixable> (fork)
1693            NOTE: perl implementation of phpass
1694    
1695    squirrelmail
1696            - wordpress <unfixed> (embed)
1697            NOTE: class-pop3.php
1698    
1699    ezSQL (http://www.woyano.com/jv/ezsql)
1700            - wordpress <unfixable> (fork)
1701            NOTE: wp-db.php
1702    
1703    Diff.php (Clay Loveless' version/killersoft.com)
1704            - php-versioncontrol-svn <unfixed>
1705    
1706    libm (provided by libc)
1707            - spring <unfixed> (embed)
1708            NOTE: embedded by embedded copy of streflop
1709            - aide <unfixed> (static)
1710            - busybox <unfixed> (static)
1711            - mindi-busybox <unfixed> (static)
1712            - qemu <unfixed> (static)
1713            NOTE: qemu-user-static
1714            - tuxonice-userui <unfixed> (static)
1715            - zsh <unfixed> (static)
1716            NOTE: zsh-static
1717    
1718    streflop
1719            - spring <unfixed> (embed)
1720    
1721    minizip
1722            - spring <unfixed> (embed)
1723    
1724    oscpack
1725            - spring <unfixed> (embed)
1726    
1727    hpiutil2
1728            - spring <unfixed> (embed)
1729    
1730    p7zip
1731            - spring <unfixed> (embed)
1732    
1733    pythonqt (doesn't seem to be python-qtN, unknown source)
1734            - fontmatrix <unfixed> (embed)
1735            - elmerfem <unfixed> (embed)
1736    
1737    iepngfix (not packaged in Debian; http://www.twinhelix.com/css/iepngfix/)
1738            - docvert <unfixed> (embed)
1739            - jifty <unfixed> (embed)
1740            - kdenetwork <unfixed> (embed)
1741            - mediatomb <unfixed> (embed)
1742            - plastex <unfixed> (embed)
1743            - plone3 <removed> (embed)
1744            - python-chaco <unfixed> (embed)
1745            - python-docutils <unfixed> (embed)
1746            - s5 <unfixed> (embed)
1747            - zope2.10 <unfixed> (embed)
1748            - zope2.11 <removed> (embed)
1749            - cython <not-affcted> (embed)
1750            NOTE: part of documentation, which is not installed into the binary package
1751    
1752    python-docutils
1753            - zope2.10 <unfixed> (embed)
1754            - zope2.11 <removed> (embed)
1755    
1756    tesseract
1757            - ocropus <unfixed> (static)
1758    
1759    antlr
1760            - kdevelop <unfixed> (embed)
1761    
1762    libxerces2
1763            - openjdk-6 <unfixed> (embed)
1764    
1765    kfreebsd-8
1766            - kfreebsd-7 <unfixed> (old-version)
1767            - kfreebsd-6 <removed> (old-version)
1768    
1769    ruby1.9.1
1770            - ruby1.9 <unfixed> (old-version)
1771            - ruby1.8 <unfixed> (old-version)
1772    
1773    maildrop
1774            - courier <unfixed> (embed) [./maildrop]
1775    
1776    glee
1777            - warzone2100 <unfixed> (embed)
1778    
1779    phing
1780            - symfony <unfixed> (embed)
1781    
1782    pake
1783            - symfony <unfixed> (embed)
1784    
1785    propel
1786            - symfony <unfixed> (embed)
1787    
1788    creole
1789            - symfony <unfixed> (embed)
1790    
1791    hfsutils
1792            - cdrkit <unfixed> (embed; bug #570187)
1793            NOTE: embeds hfsutils code in genisoimage
1794    
1795    cdrkit
1796            - grub2 <unfixed> (embed; bug #570156)
1797            NOTE: genisoimage imported into grub-mkisofs
1798    
1799    kdebase-workspace
1800            - kdebase <unfixed> (old-version)
1801    
1802    file
1803            - php5 <unfixable> (modified-embed)
1804            [lenny] - php5 <not-affected>
1805    
1806    cdb
1807            - php5 <unfixed> (embed)
1808    
1809    libmbfl (itp: #570708)
1810            - php5 <unfixed> (embed)
1811            NOTE: PHP is actually the current upstream, ITP is of that code
1812    
1813    libonig
1814            - php5 5.3.2-1 (embed)
1815    
1816    xmlrpc-epi
1817            - php5 <unfixed> (embed)
1818    
1819    swt-gtk
1820            - eclipse <unfixed> (embed; bug #538808)
1821    
1822    txt2html
1823            - wml 2.0.11ds2-1 (embed)
1824    
1825    ca-certificates
1826            - nss <not-affected> (certificates are in source, but not included in any of the binary packages)
1827    
1828    openexr
1829            - freeimage <unfixed> (embed)
1830    
1831    libmng
1832            - freeimage <unfixed> (embed)
1833    
1834    openjpeg
1835            - freeimage <unfixed> (embed)
1836    
1837    libjpeg6b
1838            - freeimage <unfixed> (embed)
1839    
1840    libjpeg (don't know what exact version)
1841            - dcmtk <unfixed>
1842            - gdcm <unfixed>
1843            - insighttoolkit <unfixed>
1844            - openarena <unfixed>
1845            - outguess <unfixed>
1846            - squeak-vm <unfixed> (embed)
1847            - tremulous <unfixed>
1848            - tuxonice-userui <unfixed> (static)
1849            - fpc <unfixed> (static)
1850            - lazarus <unfixed> (static)
1851            NOTE: inherited from fpc, see #472304
1852            - mseide-msegui <unfixed> (static)
1853            NOTE: inherited from fpc, see #472304
1854            - easymp3gain <unfixed> (static)
1855            NOTE: inherited from fpc, see #472304
1856            - winff <unfixed> (static)
1857            NOTE: inherited from fpc, see #472304
1858            - texlive-bin <not-affected> (included in upstream source as dependency of libgd2, but not built or included in any of the binary packages)
1859    
1860    libfile-copy-recursive-perl
1861            - r-base <unfixed> (embed; bug #577427)
1862            - r-base-core-ra <unfixed> (embed; bug #577429)
1863    
1864    delimmatch
1865            - r-base <unfixed> (embed; bug #577433)
1866            - r-base-core-ra <unfixed> (embed; bug #577434)
1867    
1868    libsmf (ITP: #572558)
1869            - denemo <unfixed> (embed)
1870            NOTE: http://lists.debian.org/debian-mentors/2010/04/msg00269.html
1871    
1872    libselinux
1873            - dpkg 1.15.6 (static)
1874    
1875    xinha (ITP: #479708)
1876            - horde3 <unfixed>
1877            - serendipity <unfixed>
1878            - openacs <unfixed>
1879            - dotlrn <unfixed>
1880    
1881    dvipng
1882            - texlive-bin <not-affected> (code present in source but not included in the binary packages)
1883    
1884    dvipdfmx
1885            - texlive-bin <unfixed> (embed)
1886            NOTE: this is intentionally part of the package now, and the separate dvipdfmx package has been removed from sid/squeeze
1887    
1888    lcdf-typetools
1889            - texlive-bin 2009-1 (embed)
1890    
1891    tex4ht
1892            - texlive-bin 2009-1 (embed)
1893    
1894    freetype
1895            - texlive-bin 2009-1 (embed)
1896    
1897    freetype2
1898            - texlive-bin 2009-1 (embed)
1899    
1900    silgraphite
1901            - texlive-bin <unfixed> (embed)
1902    
1903    unzip
1904            - texlive-bin 2009-1 (embed)
1905    
1906    jbig2dec
1907            - ghostscript 8.71~dfsg2-1 (embed)

Legend:
Removed from v.7923  
changed lines
  Added in v.14828

  ViewVC Help
Powered by ViewVC 1.1.5