/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7629 by nion, Sat Dec 15 17:51:31 2007 UTC revision 15644 by geissert, Fri Dec 3 01:36:53 2010 UTC
# Line 1  Line 1 
1  This file collects cases, where a source package embeds code from  Embedded code copies
2  other projects, without linking dynamically:  ====================
3    
4  xpdf code: (some use xpdf 2, some xpdf 3)  This file collects source packages that embed code from other projects.
5  gpdf (has been replaced by evince - which uses poppler - in Etch)  This is considered bad for fixing security flaws because the fix needs
6  pdftohtml (has been replaced by poppler-utils from the poppler source package, still in Etch, though)  to be applied in multiple source packages.
7  kdegraphics/kpdf (okular, the kpdf replacement in KDE 4 is using poppler, #436164)  
8  tetex-bin (links to poppler since 3.0-12)  Format:
9  texlive-bin (links to poppler)  <srcpkg> (<optional comment about srcpkg>)
10  cupsys (uses xpdf-utils, it's still present in the src, though)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11  poppler          NOTE: optional comments about the linkage of the embedding srcpkg
12  koffice/kword (upstream is working on using poppler, #436163)  
13  libextractor (uses internal pdf decoder since 0.5.12-1)  status: version number fixing the embedded copy
14  pdfkit.framework (links to poppler since 0.8-4)          <unfixed> if the issue is not yet fixed
15  ipe (only small parts, but with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp)          <removed> if the package was removed from the archive
16  ruby-gnome2 (has a copy of poppler but links against the shared lib)          <itp> if the package is in the process of being packaged
17            <not-affected> if the package does not use the embedded copy
18  silc-toolkit:          <unknown> if the version number can not be determined
19  silc-client (uses libsilc and libsilcclient)          <unfixable> for unavoidable cases (e.g., forks that add real value)
20    sort: static (linking statically against a lib)
21  dietlibc:        embed (embeds a copy of the library into another source package)
22  ccontrol (links statically)        modified-embed (embeds a code copy that differs from upstream code)
23          fork (a full-blown fork of another source package)
24  libiax:        old-version (an older version of essentially the same code)
 iaxmodem  
   
 zlib code: (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  
 dpkg  
 rsync (somehow derived code base)  
 mono  
 mozilla(?)  
 Linux kernels  
 pvpgn (links dynamically since 1.7.8-2)  
 mrtg (links dynamically since 2.12.2-1)  
 rpm  
   
 libbz2:  
 dpkg (statically linked)  
   
 libgadu/ekg:  
 centericq  
 gaim  
 pigdin (links dynamically against libgadu)  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not yet packaged in Debian)  
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 firefox (to be removed)  
 thunderbird (to be removed)  
 iceweasel  
 iceape  
 icedove  
 xulrunner  
 nvu (no longer in Debian)  
25    
26  xli:  The srcpkg might be some string to identify the code if there is no
27  xloadimage  specific source package.
28    
29  lesstif: (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  Everything up to the next line is ignored.
30  openmotif  ---BEGIN
31  xfree86/xorg (in libxpm)  poppler
32            - pdftohtml <unknown>
33  kerberized apps with BSD origin:          [sarge] - pdftohtml <unfixed>
34  krb4          [etch] - pdftohtml <unfixed>
35  krb5          NOTE: has been replaced by poppler-utils
36  heimdal          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
37            - texlive-base 3.0-12 (embed)
38  grip: (which pkg is the origin?)          - texlive-bin 2007-1 (embed)
39  libcdaudio          - koffice 1:2.0.0-1 (embed; bug #436163)
40  grip          - libextractor 0.5.12-1 (embed)
41  gnome-vfs (vfs2 as well?)          NOTE: libextractor is using its own pdf decoder now
42            - ipe <unfixed> (embed)
43  fudforum:          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44  phpgroupware-fudforum          - ruby-gnome2 <unknown> (embed)
45  egroupware-fudforum (removed from egroupware after sarge)          - pdfedit <unfixed> (embed; bug #510794)
46            - swftools <removed> (embed; bug #551293)
47  cvs:          - xpdf 3.02-9 (fork)
48  gcvs (at least an additional script is included, check if there's more)  
49    pdksh (no longer developed since 1999)
50  pcre:          - mksh <unfixable> (fork)
51  all pythons          - posh <unfixable> (fork)
52  php4 (src included, but Debian package links dynamically)  
53  analog (src included, but Debian package links dynamically)  ppmd
54  libgoffice-1          - libcomplearn-mod-ppmd <unfixed> (fork)
55  vfu (removed linking against embedded copy in 4.06-4.1; #450754)          NOTE: discussion in #458152
56  tf5 (since 5.0beta7 the Debian package links dynamically)  
57  monotone (including this starting from 0.37)  libevent
58  glib (2.14 series for gregex support, only for udeb, regular packag links dynamic)          - transmission 1.71-1 (embed; bug #529372)
59  apache2 (since 2.0.53-4 uses 040_link_external_pcre patch)          - chromium-browser 5.0.375.29~r46008-1
60  exim4 (since 4.10-0.srh20.12 uses 36_pcre patch to use external pcre)          - dnsproxy <unknown> (embed)
61  yacas (<= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway)  
62    lrmi
63  tiff:          - read-edid 2.0.0-1 (embed; bug #495131)
64  wxpythongtk (check, which debian pkg this is in)          - s3switch <unfixed> (embed)
65  older kdegraphics/kpdf releases < 3.3 embedded a copy          - xresprobe <unfixed> (embed)
66            - zhcon <unfixed> (embed)
67  uudeview:  
68  libconvert-uulib-perl  php-htmlpurifier
69            - mahara 1.2.5-1 (embed)
70  sqlite: (not affected by security vulnerabilities so far)          - knowledgeroot 0.9.9.5-5 (embed)
71  amarok          - moodle <unfixed> (embed)
72  monotone  
73  iceweasel  peercast
74            - gnome-peercast <removed> (embed)
75  util-linux/mount:          [etch] - gnome-peercast <unfixed> (embed)
76  loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb  
77    silc-toolkit
78  webmin:          - silc-client 1.1~beta6-1 (embed)
79  usermin (only in sarge)  
80    icclib
81  sylpheed:          - ghostscript <unfixed> (embed)
82  sylpheed-claws          - argyll <unfixed> (embed)
83    
84  phpsysinfo:  libusb
85  egroupware          - argyll <unfixed> (embed)
86  phpgroupware  
87    dietlibc
88  phpldapadmin:          - ccontrol 0.9.1+20071204-1 (static)
89  egroupware (removed from egroupware after sarge)          - mksh <unfixable> (static)
90            NOTE: /bin/mksh-static only, and only on some arches (others use eglibc)
91  chmlib:  
92  kchmviewer (ships the code but links dynamically)  libmikmod
93            - pysol-sound-server <unfixed> (modified-embed)
94  libavcodec/libavformat (source: ffmpeg):          - sdl-mixer1.2 <unfixed> (embed)
95  mplayer (#395252)          TODO: report bug
96  xvidcap          - uqm 0.6.2.dfsg-8 (embed)
97  kino (links statically, does not include code)          NOTE: Might be fixed earlier. Lenny version recorded.
98  vlc (links statically, does not include code)          - black-box 1.4.6-2.2 (embed)
99  smilutils (links statically, does not include code)          NOTE: Might be fixed earlier. Lenny version recorded.
100  motion (links statically, does not include code)  
101  gst-ffmpeg  libiax
102  gstreamer0.10-ffmpeg          - iaxmodem <unfixable> (embed; bug #548885)
103  xmovie  
104    spandsp
105            - iaxmodem <unfixable> (embed; bug #548885)
106    
107    python-paramiko
108            - fabric 0.9.0-2 (embed; bug #561398)
109    
110    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
111            - dpkg 1.15.6 (static)
112            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
113            - rsync <unfixed> (embed)
114            - cherokee <unfixed> (embed)
115            NOTE: somehow derived code base
116            - mono <unfixed> (embed)
117            TODO: check mozilla
118            - Linux kernels <unfixed> (embed)
119            - pvpgn 1.7.8-2 (embed)
120            - mrtg 2.12.2-1 (embed)
121            - rpm <unknown> (embed)
122            NOTE: pinged anibal since when rpm was fixed
123            - tuxcmd-modules <unfixed> (embed)
124            - zsync <unfixed>
125            - tra <unfixed>
126            - sash <unfixed>
127            - nsis <unfixed>
128            - pyfits 1:2.3.1-1
129            - mseide-msegui <unfixed>
130            NOTE: mseide
131            - mirrordir <unfixed>
132            - poco <unfixed>
133            - klibc <unfixed>
134            - emboss <unfixed>
135            - ghostscript <unfixed>
136            - freeimage <unfixed>
137            - clamav <unfixed> (fork)
138            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
139            - tuxonice-userui <unfixed> (static)
140            - plt-scheme <unfixed>
141            - perl <unfixed>
142            - paraview <unfixed>
143            - velvet 0.7.56~nozlibcopy-1
144            - gcvs <unfixed>
145            - dump <unfixed>
146            - aide <unfixed> (static)
147            - dar <unfixed> (static)
148            - avfs <unfixed>
149            - fpc <unfixed>
150            - winff <unfixed>
151            NOTE: inherited from fpc, see #472304
152            - lazarus <unfixed>
153            NOTE: inherited from fpc, see #472304
154            - erlang <unfixed> (embed)
155            - gamera 3.2.3-1 (embed)
156            - python2.4 <unfixed> (embed; bug #553403)
157            - python2.5 <unfixed> (embed; bug #553403)
158            - texlive-bin <unknown> (embed)
159    
160    dulwich
161            - hg-git 0.1.0-1 (embed; bug #541996)
162    
163    libvigraimpex
164            - hugin <unfixed> (embed; bug #542259)
165            - enblend-enfuse <unfixed> (embed; bug #542258)
166            - gamera 3.2.3-1 (embed)
167    
168    libbz2
169            - dpkg 1.15.6 (static)
170            - amd64-libs <unfixed> (static)
171            NOTE: let's call it "static"
172            - dar <unfixed> (static)
173            - dump <unfixed> (static)
174            - unalz 0.64-1 (embed)
175            NOTE: has code, by the maint, to use the system version but links against the internal copy
176            - clamav <unfixed> (embed)
177            NOTE: libclamav/nsis/bzlib*
178            - pristine-tar <unfixable> (modified-embed)
179            NOTE: compression code only, not uncompression
180            - r-base-core-ra 1.2.8 (static)
181            - r-base-core 2.11.1 (static)
182            NOTE: links dynamically in squeeze, statically in lenny
183            - rpm <unfixed> (static)
184            NOTE: lsb-rpm package is statically linked, normal rpm links dynamically
185    
186    libyahoo2
187            - centerim <unfixed> (embed; bug #559783)
188    
189    libmsn
190            - centerim <unfixed> (embed; bug #559783)
191    
192    libgadu
193            - centerim <unfixed> (embed; bug #559783)
194            - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
195            - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
196            - kdenetwork 4:3.3.2-5 (embed)
197            NOTE: from kdenetwork: kopete
198            - ekg 1:1.8~rc0-1 (embed)
199            - kadu 0.6.0.2-3 (embed; bug #504430)
200            - gadu <itp> (embed)
201    
202    xmlrpc (which package is the "origin" of this code?)
203            - drupal <unfixed> (embed)
204            - phpgroupware <unfixed> (embed)
205            - egroupware <unfixed> (embed)
206            - phpwiki <unfixed> (embed)
207            - php4 <removed> (embed)
208            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
209    
210    shtool (affects build-time only)
211            - mysql-ocaml <unfixed> (embed)
212            - php4 <removed> (embed)
213            - php5 <unfixed> (embed)
214    
215  mad MPEG decoding lib:  xulrunner
216  mad          - iceape <unfixed> (embed; bug #561749)
217  xine-lib          - iceweasel 2.0.0.19 (embed)
218            - icedove <unfixed> (embed; bug #561750)
219            - kompozer <unfixed> (embed; bug #532168)
220            - galeon 2.0.2-4 (embed)
221            - epiphany-browser 2.14.3-8 (embed)
222            - conkeror 0.9~git080629-2 (embed)
223            - kazehakase 0.4.2-1 (embed)
224    
225    xli
226            - xloadimage <unfixed> (embed)
227    
228    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
229            - openmotif <unfixed> (embed)
230    
231    libxpm
232            - lesstif2 <unfixed> (embed; bug #575750)
233    
234    kerberized apps with BSD origin
235            - krb4 <removed> (embed)
236            - krb5 <unfixed> (embed)
237            - heimdal <unfixed> (embed)
238    
239    grip (which pkg is the origin?)
240            - libcdaudio <unfixed>
241            - grip <unfixed>
242            - gnome-vfs <unfixed>
243            TODO: check vfs2 as well
244    
245    fudforum
246            [etch] - phpgroupware <unfixed> (embed)
247            NOTE: phpgroupware-fudforum
248            [sarge] - egroupware-fudforum <removed> (embed)
249    
250    libbsd
251            - rdate 1:1.2-3 (embed)
252            - atheme-services <unfixed>
253            - libbsd-arc4random-perl <not-affected> (modified-embed)
254            NOTE: code not used, it links dynamically against libbsd instead
255            - isakmpd <unfixed>
256            - bsdgames <unfixed> (embed)
257            - bsd-mailx <unfixed> (embed)
258            - netcat-openbsd <unfixed> (embed; bug #550611)
259            - openssh <unfixed> (embed)
260            - unworkable <unfixed> (embed)
261            - mksh <unfixed> (modified-embed)
262            NOTE: strlcpy(), only used in /bin/mksh-static on eglibc arches
263            NOTE: FIXME, we should only have one entry: - mksh <not-affected> (modified-embed)
264            NOTE: strlcpy() on dietlibc arches; {g,s}etmode(); both unused
265    
266    cvs
267            - gcvs <unfixed> (embed)
268            NOTE: see cvsunix/src in tarball
269    
270    pcre3
271            - php4 <removed> (embed)
272            - analog 2:5.23-0woody1 (embed)
273            - chicken 3.2.7-2 (embed)
274            NOTE: Might be fixed earlier. Lenny version recorded.
275            - goffice <unfixed> (embed)
276            NOTE: libgoffice-*
277            - hypermail 2.2.0.dfsg-2 (embed)
278            NOTE: Might be fixed earlier. Lenny version recorded.
279            - privoxy 3.0.9-1 (embed)
280            NOTE: Might be fixed earlier. Lenny version recorded.
281            - vfu 4.06-4.1 (embed; bug #450754)
282            - tf5 5.0beta7-1 (embed)
283            - monotone 0.43-1 (embed)
284            NOTE: this only affects versions >= 0.37
285            - glib2.0 2.15.2-1 (embed)
286            - apache2 2.0.53-4 (embed)
287            - exim4 4.10-0.srh20.12 (embed)
288            - yacas <unfixed> (embed)
289            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
290            - gtamsanalyzer.app 0.42-5 (embed)
291            - tin 980117-1 (embed)
292            - kazehakase 0.5.2-1
293            - webkit 1.0.1-1 (embed)
294            - qt4-x11 <unfixed> (embed)
295            NOTE: embedded via webkit copy
296            - erlang <unfixed> (embed)
297            - ssed <unfixed> (embed)
298            - ircd-hybrid <unfixed> (static)
299            - emboss <unfixd>
300            - cherokee <unfixed> (embed)
301            - oftc-hybrid 1.6.9.dfsg-1 (embed)
302            - ratbox-services <unfixed> (embed)
303            - squeak-vm <unfixed> (embed)
304            - tinymux <unfixed> (embed)
305    
306    tiff
307            - wxwindows2.4 2.2.1 (embed)
308            - gamera 3.2.3-1 (embed)
309            - freeimage <unfixed> (embed)
310            - libtk-img <unfixed> (embed)
311            NOTE: there are two copies, one under tiff/ other under libtiff/
312            - gdal <unfixed>
313    
314    uudeview
315            - libconvert-uulib-perl <unfixed> (embed)
316            - pan <unfixed> (embed)
317    
318    sqlite (not affected by security vulnerabilities so far)
319            - amarok <unfixed> (embed)
320            - monotone 0.43-1 (embed)
321            - iceweasel <unfixed> (embed)
322            - heimdal <unfixed> (embed; bug #559616)
323    
324    util-linux/mount
325            - loop-aes-utils <unfixed> (embed)
326            NOTE: contains code from util-linux' mount in the mount-aes-udeb
327    
328    sylpheed
329            - sylpheed-claws <unfixed> (fork)
330    
331    phpsysinfo
332            - egroupware <unfixed> (embed)
333            - phpgroupware <unfixed> (embed)
334    
335    phpldapadmin
336            [sarge] - egroupware <unfixed> (embed)
337            NOTE: removed from egroupware after sarge
338    
339    chmlib
340            - kchmviewer <unknown> (embed)
341    
342    ffmpeg (libavcodec/libavformat)
343            - mplayer 1.0~rc2-14 (embed; bug #395252)
344            - kino 1.0.0-1
345            - vlc <not-affected> (Links dynamically since initial release)
346            - smilutils 0.3.0-10
347            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
348            - motion 3.1.19-1
349            - gstreamer0.10-ffmpeg 0.10.3-2
350            - xmovie <removed> (static)
351            TODO: gimp-gap (potentially using ffmpeg code as well)
352            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
353            - audacity 1.3.7-2 (embed; bug #512278)
354            - chromium-browser <unfixed> (fork)
355    
356    faad2
357            - mplayer 1.0~rc2-20 (embed)
358            - avifile <unfixed> (embed; bug #538750)
359            - ffmpeg-debian <removed> (embed)
360    
361    libmad (MPEG decoding lib)
362            - xine-lib <unfixed> (embed)
363            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
364            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
365    
 libdts:  
366  libdts  libdts
367  xine-lib          - xine-lib <unfixed> (embed)
368    
 flac:  
369  flac  flac
370  xine-lib          - xine-lib <unfixed> (embed)
371    
372  liba52:  liba52
373  a52dec          - a52dec <unfixed> (embed)
374  xine-lib          - xine-lib <unfixed> (embed)
375    
376    mpeg2dec (libmpeg2)
377            - xine-lib <unfixed> (embed)
378    
379    libmpeg3
380            - squeak-vm <unfixed> (embed)
381    
382    libntlm
383            - wget <unfixed> (fork; bug #550436)
384            - curl <unfixed> (fork; bug #550437)
385            - cntlm <unfixed> (fork; bug #550438)
386    
387    uw-imap
388            - pine <unfixed> (embed)
389            - alpine <unfixed> (embed)
390    
391    imagemagick
392            - graphicsmagick <unfixed> (fork)
393    
394    python-urlgrabber
395            - mercurial <unfixed> (embed; bug #531062)
396            - w3af <unfixed> (embed; bug #555372)
397            [experimental] - harvestman <unfixed> (embed; bug #555373)
398    
399    beautifulsoup
400            - python-mechanize <unfixed> (embed; bug #555349)
401            - zope2.11 <removed> (embed; bug #555350)
402            - twill <unknown> (embed)
403    
404    halibut
405            - nsis <unfixed> (fork)
406    
407    libghttp
408            - hotway <unfixed> (embed)
409    
410    libsndfile
411            - ardour 1:2.7.1-1 (embed)
412    
413    glibmm2.4
414            - ardour 1:2.7.1-1 (embed)
415    
416    libgnomecanvasmm2.6
417            - ardour 1:2.7.1-1 (embed)
418    
419    libsigc++-2.0
420            - ardour 1:2.7.1-1 (embed)
421    
422    soundtouch
423            - ardour 1:2.7.1-1 (embed)
424    
425    libmms
426            - xine-lib <unfixed> (embed)
427            - mimms <unfixed> (embed)
428    
429    fckeditor
430            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
431            - moin 1.8.2-2 (embed; bug #452599)
432            - karrigell <removed> (embed; bug #452598)
433            - gforge 4.6.99+svn6225-1 (embed)
434            - request-tracker3.8 <unfixed> (embed)
435            - otrs2 <unfixed> (embed)
436    
437    ipatlas (not packaged in Debian)
438            - moodle <unfixed> (embed; bug #507185)
439    
440    libphp-phpmailer
441            - moodle <unfixed> (embed; bug #507185)
442            - mahara <unfixed> (embed)
443            - symfony <unfixed> (embed; bug #566778)
444            [etch] - phpgroupware <unfixed> (embed)
445            NOTE: phpgroupware-felamimail is only in etch
446            - egroupware <unfixed> (embed; bug #504283)
447            - glpi <unfixed>
448    
449    htmlArea (not packaged in Debian)
450            - moodle <unfixed> (embed)
451    
452    giflib
453            - wine <unfixed> (embed; bug #466181)
454    
455    bennu (not packaged in Debian, http://bennu.sourceforge.net)
456            - moodle <unfixed> (embed)
457    
458    smarty
459            - moodle 1.8.2-2 (embed; bug #471158)
460            - gallery2 2.2.5-2 (embed; bug #471160)
461            - mahara 0.9.2-2 (embed; bug #471201)
462            - gosa 2.4beta1-1 (embed; bug #471200)
463    
464    TinyMCE
465            - wordpress 2.5.1-3 (embed; bug #478257)
466            - moodle <unfixed> (embed; bug #507185)
467            - knowledgeroot <unfixed> (embed)
468            - joomla <itp> (bug #326398)
469            - mahara 1.2.6-1 (embed; #597752)
470    
471    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
472            - scite <unfixed> (embed)
473            - qscintilla <unfixed> (embed)
474            - qscintilla2 <unfixed> (embed)
475            - geany <unfixed> (fork)
476            - anjuta <unfixed> (embed)
477    
478    libphp-adodb
479            - moodle <unfixed> (embed; bug #507185)
480            NOTE: also AdoDB-XML Schema
481            - gallery2 <unfixed> (embed)
482            - phppgadmin <unfixed> (embed)
483            - egroupware <unfixed> (embed)
484            - phpwiki <unfixed> (embed)
485            - torrentflux 2.0beta1-2 (embed)
486            - ipplan <unfixed> (embed)
487            - typo3-src <unfixed> (embed)
488            - cacti <unknown> (embed)
489            [sarge] - cacti <unfixed> (embed)
490            NOTE: dependency exists, but internal version is used
491            - gforge 4.7~rc2-6 (embed)
492            - mahara <unfixed> (embed)
493    
494    gzip
495            - linux-2.6 <unfixed> (embed) [lib/inflate.c]
496            - klibc <unfixed> (embed)
497            NOTE: based on linux-kernel gzip code
498            - busybox <unfixed> (embed)
499            - pristine-tar <unfixed> (modified-embed)
500            NOTE: compression code only, not uncompression
501            - ncompress <unfixed> (old-version)
502    
503    neon
504            - cadaver 0.22.3+debian-1 (embed; bug #188381)
505            - gnome-vfs2 <unfixed> (embed; bug #395874)
506            [etch] - litmus <unfixed> (embed; #395875)
507            - litmus <removed> (embed; #395875)
508            [sarge] - screem <unfixed> (embed)
509            - sitecopy 1:0.16.0-1 (embed; bug #395876)
510            [etch] - tla <unfixed> (embed; bug #395877)
511            [sarge] - tla <unfixed> (embed; bug #395877)
512    
513    libmodplug
514            - gst-plugins-bad0.10 0.10.10.2-1 (embed)
515    
516    libvncserver
517            - vino <unfixed> (embed)
518    
519    putty
520            - filezilla <unfixed> (embed)
521    
522    tinyxml (not packaged in Debian; itp bug #531968)
523            - filezilla <unfixed>
524            - crystalspace <unfixed> (embed)
525            - libwfut <unfixed> (embed)
526            - rarian <unfixed> (embed)
527            - bulletml <unfixed> (embed)
528            - pokerth <unfixed> (embed)
529            - qutecom <unfixed> (embed)
530            - sofa-framework <unfixed> (embed)
531            - yate <unfixed> (embed)
532            - antigrav <unfixed> (embed)
533            - balder2d <unfixed> (embed)
534            - cal3d <unfixed> (embed)
535            - criticalmass <unfixed> (embed)
536            - ember <unfixed> (embed)
537            - epiphany <unfixed> (embed)
538            - gambit <unfixed> (embed)
539            - noiz2sa <unfixed> (embed)
540            - ogre <unfixed> (embed)
541            - opencity <unfixed> (embed)
542            - openmovieeditor <unfixed> (embed)
543            - pouetchess <unfixed> (embed)
544            - tecnoballz <unfixed> (embed)
545            - trigger-rally <unfixed> (embed)
546            - xmoto <unfixed> (embed)
547            - mapnik <unknown> (embed)
548            NOTE: uses a different XML parser by default
549            - rrootage 0.23a-6 <embed>
550            NOTE: links to libbulltetml
551            - boson <unknown> (embed)
552            NOTE: the embedded code is unused
553    
554    gv
555            - evince <unfixed> (embed)
556            NOTE: ps/ tree from gv 3.5.8
557            NOTE: evince-gtk is affected (a component of evince source package)
558    
559    libXbae
560            - paw <unfixed> (embed)
561    
562    libgtkhtml
563            - claws-mail-extra-plugins <unfixed> (fork)
564    
565    libXaw
566            - paw <unfixed> (embed)
567            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
568    
569    libgd2
570            - graphviz <unfixed> (embed)
571            NOTE: lib/gd seems to be 2.0.33
572            - wml 2.0.11ds2-1 (embed)
573            - libwmf <unfixed> (embed)
574            NOTE: derived from gd 1.6.3
575            - plt-scheme <unfixed> (embed; bug #601525)
576            - texlive-bin 2009-1 (embed)
577    
578    rar
579            - unrar-nonfree <unfixed> (embed)
580    
581    unrar-free (maybe this code is derived from the original rar, too?)
582            - clamav <unfixed> (embed)
583            NOTE: seems to be disabled in default config
584    
585    mplayer (DirectMedia Object loader)
586            - xine-lib <unfixed> (embed)
587            NOTE: src/libw32dll/
588            - vlc <unfixed> (embed)
589            NOTE: modules/codec/dmo/
590            - mplayer 1.0~rc2-20 (embed)
591    
592    libwpd (WordPerfect converter)
593            - openoffice.org <unfixed> (embed)
594    
595    fsplib (http://sourceforge.net/projects/fsp/)
596            - gftp <unfixed> (embed)
597            NOTE: lib/fsplib version 0.3
598    
599    sprng
600            - tree-puzzle <unfixed> (embed)
601    
602    librpcsecgss
603            - krb5 <unfixed> (embed)
604    
605    jasper
606            - ghostscript 8.64~dfsg-2 (embed)
607    
608    libiris
609            - psi <unfixed> (embed)
610            - kdenetwork <unfixed> (embed)
611            NOTE: kopete embeds libiris but links dynamically to libidn
612            - kdegames <unfixed> (embed)
613            NOTE: ksirk/kde4
614    
615    libidn
616            - monotone 0.43-1 (embed)
617            - psi <unfixed> (embed)
618            NOTE: psi embeds libiris which embeds libidn
619            - kdegames <unfixed> (embed)
620            NOTE: kdegames/kde4 embeds libiris which embeds libidn
621    
622    lua5.1
623            - monotone 0.43-1 (embed)
624            - nmap 5.00-1 (embed; bug #527997)
625            [lenny] - nmap <unfixed> (embed; bug #527997)
626            - ocropus <unfixed> (embed)
627            - enigma <unfixed> (embed)
628            NOTE: requires lua built with C++
629            - freeciv <unfixed> (embed)
630            - spring <unfixed> (embed)
631    
632    libbotan
633            - monotone 0.43-1 (embed)
634    
635    NetXX
636            - monotone 0.43-1 (embed)
637    
638    libgc
639            - mono <unfixed> (embed)
640    
641    lzma
642            - p7zip <unfixed> (embed)
643            - xz-utils <unfixed> (fork)
644            - r-base <unfixed> (embed)
645            NOTE: lzma support not yet in lenny or in r-base-core-ra 1.2.8
646    
647    lzo
648            - grub2 <unfixed> (embed)
649    
650    yassl
651            - mysql-dfsg-5.0 <unfixed> (embed)
652            - mysql-5.1 <unfixed> (embed)
653    
654    pax code
655            - tar <unfixed> (embed)
656            - cpio <unfixed> (embed)
657    
658    t1lib
659            - tetex-bin 2.0.2-1 (embed)
660            - texlive-bin <unknown> (embed)
661            - grace 5.1.14-2 (embed)
662            NOTE: Might be fixed even earlier
663    
664    guichan
665            - boswars <unfixed> (embed)
666            NOTE: maintainer notified us, working on it
667    
668    tolua
669            - boswars <unfixed> (embed)
670            NOTE: maintainer notified us, working on it
671            NOTE: actually tolua++
672            - ocropus <unfixed> (embed)
673            NOTE: actually tolua++
674            - freeciv <unfixed> (embed)
675            NOTE: actually tolua++
676            - enigma <unfixed> (embed)
677    
678    asio-dev
679            - luxrender <removed> (embed)
680    
 libmpeg2:  
 mpeg2dec  
681  xine-lib  xine-lib
682            - vlc <unfixed> (embed)
683            NOTE: only parts included in modules/access/rtsp
684    
685  curl:  netpbm
686  wget (code for NTLM authentication)          - tcl8.3 <unfixed> (embed)
687            - tcl8.4 <unfixed> (embed)
688            - tcl8.5 <unfixed> (embed)
689            NOTE: generic/tkImgGIF.c
690    
691    tk8.5
692            - tk8.0 <removed> (old-version)
693            - tk8.3 <unfixed> (old-version)
694            - tk8.4 <unfixed> (old-version)
695            - perl-tk <unfixable> (fork)
696    
697    samba
698            - mc 2:4.6.2~git20080311-1 (embed)
699            NOTE: maintainer is aware of this, currently searching a solution
700    
701    plib1.8.4c2
702            - boson <unfixed> (fork)
703            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
704    
705    fribidi
706            - quesoglc 0.7.2-2 (embed)
707    
708    glew
709            - quesoglc <unfixed> (embed; bug #489341)
710            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
711            - trigger 0.5.2.1-2 (embed)
712            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
713            - trigger-rally 0.5.2.1-2 (embed)
714            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
715            - chromium-browser 5.0.375.70~r48679-2
716    
717    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
718            - transcend <unfixed> (embed)
719            - cultivation <unfixed> (embed)
720            - passage <unfixed> (embed)
721            - gravitation <unfixed> (embed)
722    
723  TODO evaluate:  tar
724  gimp-gap (potentially using ffmpeg code as well)          - libarchive <unfixed> (embed)
725            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
726    
727  uw-imap:  cpio
728  pine          - libarchive <unfixed> (embed)
729  alpine          NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
730    
731  imagemagick:  kde4libs
732  graphicsmagick          - kdelibs <unfixable> (old-version)
733    
734  halibut:  webkit
735  nsis          - qt4-x11 <unfixed> (embed; bug #479851)
736            [etch] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
737            - kde4libs <unfixable> (fork)
738            NOTE: kde4lib's khtml and webkit were forked from khtml (this tracking, which seems
739            NOTE: reversed genesis-wise, is used because of so much other stuff in kde4libs)
740            - chromium-browser <unfixed> (fork)
741    
742    ftgl
743            - blender 2.46+dfsg-1 (embed)
744    
745    wv
746            - abiword <unfixed>
747    
748    qemu
749            - kvm <removed> (embed; bug #543159)
750            - qemu-kvm <unfixed> (embed; bug #560853)
751            NOTE: kvm superceded by qemu-kvm, which is just user interface (no modules)
752            - xen-3 3.4.2-2 (embed; bug #560856)
753            - xen-unstable <unfixed> (embed; bug #560856)
754    
755    vgabios
756            - kvm <removed> (embed; bug #489442)
757            - qemu-kvm <unfixed> (embed)
758    
759    bochs
760            - kvm <removed> (embed; bug #489442)
761            - qemu-kvm <unfixed> (embed)
762    
763    speex
764            - vorbis-tools <unfixed> (embed)
765            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
766            - gst-plugins-good0.10 <unfixed> (embed)
767            - xine-lib <unfixed> (embed)
768            - libfishsound <unfixed> (embed)
769            - libannodex <removed> (embed)
770            - opal 3.4.2~dfsg-2 (embed)
771            - mumble 1.2.0~beta1-1 (embed)
772            - vlc <unfixed> (embed)
773            - xmms-speex <unfixed> (embed)
774            - libsdl-sound1.2 <unfixed> (embed)
775            - sweep <unfixed> (embed)
776    
777    libreadline
778            - magic <itp> (old-version)
779    
780    opcode
781            - ode <unfixed> (embed)
782            NOTE: opcode is not a package in debian, it is just embedded
783            NOTE: http://www.codercorner.com/Opcode.htm
784    
785    gimpact
786            - ode <unfixed> (embed)
787            NOTE: gimpact is not a package in debian, it is just embedded
788            NOTE: http://gimpact.sf.net
789    
790    mochikit
791            - mahara <unfixed> (embed)
792            NOTE: they require extra patches, still unmerged upstream
793            - ntop <unfixed> (embed)
794            - coherence 0.6.2-1 (embed)
795            - paste <unfixed> (embed)
796            - turbogears <unfixed> (embed)
797            - plone3 <removed> (embed)
798            - xulrunner <unfixed> (embed)
799            - libjifty-plugin-chart-perl <unfixed> (embed)
800            - sabnzbdplus <unfixed> (embed)
801            - tgmochikit <unfixed> (embed)
802    
803    prototypejs
804            - netbeans-ide 6.0.1+dfsg-2 (embed)
805            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
806            - webcit <unfixed> (embed; bug #555219)
807            - asterisk 1:1.6.2.0~rc3-1 (embed)
808            - libjson-ruby 1.1.4-1 (embed; bug #555224)
809            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
810            - horde3 <unfixed> (embed)
811            - knowledgeroot 0.9.8.5-4 (embed; bug #555230)
812            - mediatomb 0.12.0~svn2018-5 (embed; bug #555233)
813            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
814            - ebug-http <unfixed> (embed; bug #555236)
815            - libaws 2.7-1 (embed; bug #555222)
816            - phpgedview <removed> (embed)
817            - poker-network 1.7.6-1 (embed; bug #555238)
818            - rails 2.1.0-6 (embed)
819            - wordpress 2.5.0-2 (embed; bug #555243)
820            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
821            TODO: search through all of the other zope packages
822            - ampache 3.4.1-2 (embed)
823            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
824            - hobix 0.5~svn20070319-4 (embed; bug #555247)
825            - zabbix 1.6.6-4 (embed; bug #555250)
826            - chora2 2.1.1+debian0-1 (embed; bug #555253)
827            - gollem 1.1.1+debian0-1 (embed; bug # 555254)
828            - jscropperui 1.2.1-1 (embed; bug #555257)
829            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
830            - ingo1 1.2.3+debian0-1 (embed; bug #555261)
831            - kronolith2 2.3.3+debian0-1 (embed; bug #555262)
832            - activeldap 1.2.1-1 (embed)
833            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
834            - mantis 1.1.2+dfsg-1 (embed; bug #555265)
835            - otrs2 2.3.4-6 (embed; bug #555267)
836            - webcalendar 1.2~b1-2 (embed; bug #555269)
837            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
838            - jifty 0.90519-1 (embed; bug #555271)
839            - jquery 1.4-1 (embed; bug #555272)
840            - passenger 2.2.5debian1-1 (embed; bug #555273)
841            - plone3 <removed> (embed; bug #555275)
842            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
843            - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
844            - xulrunner <unfixed> (embed)
845            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
846            - jclicmoodle <unfixed> (embed)
847            - git-cola <unfixed> (embed)
848    
849    gdb
850            - insight <unfixed> (embed)
851    
852    e2fsprogs
853            - ldiskfsprogs <unfixable> (fork)
854    
855    quazip (not packaged in Debian)
856            - qcake <unfixed> (embed)
857            NOTE: starting with upstream version 0.6.4
858    
859    exo
860            - pcmanfm <unfixed> (embed; bug #499677)
861            NOTE: slightly modified source code
862    
863    java
864            - openjdk-6 <unfixed>
865            - sun-java5 <unfixed>
866            - sun-java6 <unfixed>
867    
868    libphp-snoopy
869            - ampache 3.4.1-2 (embed; bug #504169)
870            - gforge 4.6.99+svn6094-2 (embed)
871            - mahara 1.0.5-2 (embed; bug #504170)
872            - pixelpost 1.7.1-5 (embed; bug #504171)
873            - mediamate 0.9.3.6-5 (embed; bug #504172)
874            - opendb <removed> (embed; bug #504173)
875            [etch] - opendb <unfixed> (embed; bug #504173)
876            - wordpress 2.5.1-9 (embed; bug #443948)
877            - moodle <unfixed> (embed; bug #507185)
878            [etch] - phpgroupware <unfixed> (embed)
879            NOTE: phpgroupware-felamimail
880            - magpierss 0.72-3 (embed; bug #431089)
881    
882    jquery
883            - zekr <unfixed> (embed)
884            - wordpress <unknown> (embed)
885            - yocto-reader <unfixed> (embed)
886            - textpattern <unfixed> (embed)
887            - genshi 0.5.1-1 (embed)
888            NOTE: compressed file under examples/ dir
889            - prewikka <unfixed> (embed)
890            - libramaze-ruby <unfixed> (embed)
891            - drupal6 <unfixed> (embed)
892            - b2evolution <unfixed> (embed)
893            - wesnoth <unfixed> (embed)
894    
895    tablesorter (jquery plugin, not packaged yet)
896            - wesnoth <unfixed> (embed)
897    
898    kses
899            - wordpress <unfixed> (embed; bug #504242)
900            NOTE: their copy has all methods renamed to wp_<foo>
901            NOTE: kses isn't in Debian, RFP: #504240
902            - moodle <unfixed> (embed; bug #507185)
903            - egroupware <unfixed> (embed)
904    
905    magpierss
906            - wordpress <unfixed> (embed; bug #504242)
907            - moodle <unfixed>
908    
909    php-gettext
910            - wordpress 2.8.4-1 (embed; bug #504242)
911            - docbookwiki <unfixed> (embed)
912            - knowledgeroot 0.9.9.5-1
913            NOTE: non-free
914    
915    libphp-ixr (name may change, it is the Incutio XML-RPC)
916            - wordpress <unfixed> (embed; bug #504242)
917            NOTE: libphp-ixr isn't in Debian, RFP: #504236
918            - dokuwiki <unfixed> (embed)
919            - textpattern <unfixed> (embed)
920    
921    libphp-cas
922            - glpi <unfixed> (embed)
923            - moodle <unfixed> (embed; bug #505984)
924    
925    scriptaculous (prototype.js is among the embeds in the following)
926            - glpi <unfixed> (embed)
927            - libaws <unfixed> (embed; bug #555222)
928            - op-panel <unfixed> (embed)
929            - symfony <unfixed> (embed)
930            NOTE: maintainer says there are extra incompatible changes required
931            - pixelpost 1.7.1-6 (embed)
932            - webhelpers <unfixed> (embed)
933            - qwik <removed> (embed; bug #555241)
934            - smokeping <unfixed> (embed)
935            - turba2 <unfixed> (embed)
936            - typo3-src 4.2.3-1 (embed)
937            - request-tracker3.6 <unfixed> (embed)
938            - request-tracker3.8 <unfixed> (embed)
939            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
940            - wordpress 2.5.0-2 (embed)
941            - libhtml-prototype-perl 1.48-3 (embed)
942    
943    libmarkdown-php
944            - moodle <unfixed> (embed; bug #507185)
945            - pixelpost 1.7.1-6 (embed)
946    
947    php-openid
948            - wordpress-openid 3.3.2-1 (embed)
949    
950    geshi
951            - dokuwiki 0.0.20080505-3.1 (embed)
952            - pgfouine 1.0-1.1 (embed)
953            - websvn 2.1.0-1 (embed)
954    
955    webcalendar
956            - gforge 4.7~rc2-6 (embed; bug #504758)
957    
958    libical
959            - kdepim <unknown> (fork)
960            NOTE: fixed at some point during 4.0
961            - kdepimlibs 4.2.0-1 (fork)
962            - claws-mail-extra-plugins <unfixed> (fork)
963    
964    harfbuzz
965            - qt4-x11 <unfixed> (embed)
966            - pango1.0 <unfixed> (embed)
967            - fontmatrix <unfixed> (embed)
968    
969    libzip
970            - php5 <unfixable> (modified-embed)
971            - odt2txt <unfixed> (embed; bug #523808)
972    
973    json.php (not packaged; should be replaced with php's built-in functions)
974            - moodle <unfixed>
975            - yui <unfixed>
976            - gallery2 <unfixed>
977            - dokuwiki <unfixed>
978            - typo3-src <unfixed>
979    
980    php-fpdf
981            - tcpdf <itp> (fork)
982            - moodle <unfixed>
983            - phpwiki <unfixed>
984            - egroupware <unfixed>
985            - ldap-account-manager <unfixed> (fork)
986    
987    tcpdf (itp: #495985)
988            - moodle <unfixed>
989            - phpmyadmin <unfixed>
990    
991  libghttp:  typo3
992  hotway          - moodle <unfixed>
993    
994    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
995            - moodle <unfixed>
996            - gosa <unfixed>
997    
998    php-ole (itp: #487558)
999            - moodle <unfixed>
1000    
1001    pieforms (http://www.catalyst.net.nz)
1002            - mahara <unfixed>
1003    
1004    savant2 (http://phpsavant.com)
1005            - egroupware <unfixed>
1006    
1007    rssparser (http://nwow.org)
1008            - egroupware <unfixed>
1009            - phpgroupware <unfixed>
1010    
1011    lcms
1012            - openjdk-6 <unfixed> (fork)
1013            - gimp 2.4.0~rc2-2
1014    
1015    libphp-phplayersmenu
1016            - diogenes <unfixed>
1017            - phpldapadmin <unfixed>
1018    
1019    libphp-pclzip
1020            - docvert <unfixed>
1021            - moodle <unfixed>
1022            - egroupware <unfixed>
1023    
1024    libphp-simplepie
1025            - dokuwiki <unfixed>
1026            - wordpress <unfixed>
1027    
1028    libphp-jpgraph
1029            - egroupware <unfixed>
1030    
1031    php-simpletest
1032            - moodle <unfixed>
1033    
1034    libpng
1035            - doxygen 1.5.6-2 (embed)
1036            NOTE: Might be fixed earlier. Lenny version recorded.
1037            - gdal 1.5.2-3 (embed)
1038            NOTE: Might be fixed earlier. Lenny version recorded.
1039            - iceweasel <not-affected> (uses xulrunner)
1040            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
1041            - iceape 1.0.13~pre080614i-0etch1 (embed)
1042            - libfltk1.1 1.1.9-6 (embed)
1043            NOTE: Might be fixed earlier. Lenny version recorded.
1044            - libtk-img <unfixed> (embed)
1045            - htmldoc 1.8.27-3 (embed)
1046            NOTE: Might be fixed earlier. Lenny version recorded.
1047            - xulrunner 1.9.0.13-1 (embed)
1048            [lenny] - xulrunner 1.9.0.11-0lenny1
1049            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1050            - gamera 3.2.3-1 (embed)
1051            - freeimage <unfixed> (embed)
1052            - syslinux-common <unfixable> (embed)
1053            - tuxonice-userui <unfixed> (static)
1054            - texlive-bin 2007.dfsg.2-1~lenny2 (embed)
1055            NOTE: Might be fixed earlier. Lenny version recorded.
1056            - vice 1.22.dfsg1-0.1 (embed)
1057            NOTE: Might be fixed earlier. Lenny version recorded.
1058            - visualboyadvance 1.8.0-4 (embed)
1059            NOTE: Might be fixed earlier. Lenny version recorded.
1060    
1061    irssi
1062            - silc-client <unfixed> (embed)
1063            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
1064    
1065    extc
1066            - mtasc <unfixed> (embed)
1067            - haxe <unfixed> (embed)
1068    
1069    swflib
1070            - mtasc <unfixed> (embed)
1071            - haxe <unfixed> (embed)
1072    
1073    libitext-java
1074            - bouncycastle 2.1.4-1 (embed)
1075    
1076    python-ply
1077            - pyke <unfixed> (embed; bug #555363)
1078            - pywbem 0.7.0-4 (embed; bug #555364)
1079            - sepolgen <unfixed> (embed; bug #555365)
1080            - zope-textindexng3 <unknown> (embed)
1081            - iceweasel <not-affected> (uses xulrunner)
1082            - xulrunner <unknown> (embed)
1083            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
1084    
1085    libdumbnet (libdnet upstream)
1086            - nmap <unfixed> (fork)
1087    
1088    gcc-4.4
1089            - gcc-mingw32 <unfixed> (embed)
1090    
1091    camlimages
1092            - advi <unfixed> (static; bug #550441)
1093    
1094    memcached
1095            - memcachedb <unfixed> (embed)
1096    
1097    yajl
1098            - argyll <unfixed> (embed; bug #544223)
1099            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
1100    
1101    nusoap
1102            - gforge 4.8.2-1 (embed)
1103            - ampache <unfixed> (embed)
1104            - poker-network <unfixed> (embed)
1105            - moodle <unfixed> (embed)
1106            NOTE: code is not used when running under php5 and soap is enabled
1107            - phpwiki <unfixed> (embed)
1108            - gallery2 <unfixed> (embed)
1109            - typo3-src <unfixed> (embed)
1110            - phpgacl 3.3.7-7 (embed)
1111            - mantis 1.1.8+dfsg-1 (embed)
1112    
1113    libept
1114            - adept <unfixed> (embed; bug #540649)
1115    
1116    libvorbis
1117            - iceweasel <not-affected> (uses xulrunner)
1118            - xulrunner <unfixed> (embed; bug #540959)
1119            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1120            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1121            - iceape <unfixed> (embed)
1122            [etch] - iceape <not-affected> (introduced in 2.0)
1123            [lenny] - iceape <not-affected> (introduced in 2.0)
1124    
1125    cairo
1126            - iceweasel <not-affected> (uses xulrunner)
1127            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1128    
1129    liboggz
1130            - iceweasel <not-affected> (uses xulrunner)
1131            - xulrunner <unfixed> (embed; bug #540959)
1132            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1133            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1134            - iceape <unfixed> (embed)
1135            [etch] - iceape <not-affected> (introduced in 2.0)
1136            [lenny] - iceape <not-affected> (introduced in 2.0)
1137    
1138    liboggplay
1139            - iceweasel <not-affected> (uses xulrunner)
1140            - xulrunner <unfixed> (embed; bug #540959)
1141            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1142            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1143            - iceape <unfixed> (embed)
1144            [etch] - iceape <not-affected> (introduced in 2.0)
1145            [lenny] - iceape <not-affected> (introduced in 2.0)
1146    
1147    php-net-dnsbl
1148            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1149    
1150    php-onyx-rss
1151            - serendipity <unfixed> (embed; bug #541740; wontfix: only one script, own package is overkill, appears not to be duplicated in Debian)
1152    
1153    php-text-wiki
1154            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1155    
1156    php-xml-rpc
1157            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1158    
1159    polarssl (does not have a shared library)
1160            - pdkim <itp> (embed; bug #543150)
1161            - xyssl <unfixed> (old-version)
1162    
1163    pidgin (libpurple)
1164            - gaim <removed> (old-version)
1165            - qutecom 2.2~rc3.hg396~dfsg1-6 (embed; bug #559785)
1166            - wengophone <unfixed> (embed; bug #601425)
1167    
1168    icu
1169            - webkit 1.0.1-1 (embed; bug #547214)
1170            - texlive-bin <unfixed> (fork)
1171            NOTE: texlive upstream working with icu upstream to merge their changes
1172            - chromium-browser 5.0.375.29~r46008-3
1173    
1174    cyrus-imapd-2.2
1175            - kolab-cyrus-imapd <unfixed> (fork)
1176            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1177    
1178    python-cxx-dev
1179            - freecad 0.9.2646.3-1 (embed; bug #547936)
1180    
1181    zipios++
1182            - freecad 0.9.2646.3-1 (embed; bug #547941)
1183            - enigma 0.92.3-3 (embed)
1184            NOTE: likely fixed earlier, marking etch's version as fixed
1185    
1186    linux-2.6
1187            - kvm <removed> (embed; bug #549973) [./kernel/*]
1188            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1189            - kernel-source-2.6.8 <removed> (old-version)
1190            - kernel-source-2.4.27 <removed> (old-version)
1191            - kernel-source-2.4.24 <removed> (old-version)
1192            - kernel-source-2.2.25 <removed> (old-version)
1193            - kernel-source-2.2.20 <removed> (old-version)
1194    
1195    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1196            - kvm <removed> (embed) [./libfdt/*]
1197            - qemu-kvm <unfixed> (embed) [./libfdt/*]
1198    
1199    qweb (not packaged)
1200            - ajaxterm <unfixed>
1201    
1202    opensaml2
1203            - opensaml <removed> (old-version)
1204    
1205    shibboleth-sp2
1206            - shibboleth-sp <removed> (old-version)
1207    
1208    tuxonice-userui
1209            - suspend2-userui <removed> (old-version)
1210    
1211    expat
1212            - w3c-libwww <removed> (embed; bug #551941)
1213            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1214            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1215            - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1216            - python2.4 <unfixable> (embed; bug #553403)
1217            - python2.7 2.7-6 (embed)
1218            - mcabber 0.10.0-1 (low; bug #601053)
1219            - python-4suite <unfixed> (embed; bug #516935)
1220            - wxwindows2.4 <removed> (embed)
1221            - wxwidgets2.6 2.6.3.2.2-4 (embed)
1222            - wxwidgets2.8 2.8.10.1-2 (embed)
1223            - albert <unfixed> (embed; bug #600974)
1224            - celementtree 1.0.5-8 (embed)
1225            NOTE: Maybe that was fixed even earlier
1226            - centerim <unfixed> (embed; bug #559783)
1227            - audacity 1.3.2-1 (embed)
1228            - matanza <unfixed> (embed)
1229            - tdom 0.8.3~20080525-1 (embed)
1230            - udunits 2.1.8-4 (embed)
1231            - apr-util 1.2 (embed)
1232            - ayttm <unfxed> (embed; bug #561006)
1233            - cableswig <unfixed> (embed)
1234            - cadaver <unfixed> (embed)
1235            - cmake 2.6.0-6 (embed)
1236            - coin3 <unfixed> (embed)
1237            - cvsnt 2.5.03.2382-3.3+lenny1 (embed)
1238            NOTE: Might be fixed earlier. Lenny version recorded.
1239            - dasher 4.7.3-1 (embed)
1240            NOTE: Might be fixed earlier. Lenny version recorded.
1241            - gdcm 2.0.14-2 (embed)
1242            - ghostscript 8.71~dfsg-2 (embed)
1243            - grmonitor <removed> (embed)
1244            - iceape <unfixed> (embed)
1245            - insighttoolkit 3.16.0-1 (embed)
1246            NOTE: insighttoolkit might've been fixed earlier
1247            - jabber 1.4.3-3.4 (embed)
1248            NOTE: Might be fixed earlier. Lenny version recorded.
1249            - libparagui1.1 1.0.2-1 (embed)
1250            - libspiff1 0.8.3-1 (embed)
1251            NOTE: Might be fixed earlier. Lenny version recorded.
1252            - paraview 3.6.2-1 (embed)
1253            - poco 1.3.6p1-1 (embed)
1254            - scorched3d 41.3dfsg-1+b1 (embed)
1255            NOTE: Might be fixed earlier. Lenny version recorded.
1256            - simgear <unfixed> (embed)
1257            - sitecopy 1:0.16.0-1
1258            - smart <unfixed> (embed)
1259            NOTE: smart embeds celementree, and it includes expat
1260            - swish-e <not-affected> (Linked against libxml, which is used instead)
1261            - tla 1.3.5+dfsg-15 (embed)
1262            - vtk 4.1.20030227-1 (embed)
1263            - wbxml2 <not-affected> (expat code is only used on Mac OS X, see #560941)
1264            - xmlrpc-c <unfixed> (embed)
1265            - iceweasel <unfixed> (embed)
1266            - kompozer <unfixed> (embed)
1267            - vxl 1.13.0-2 (embed)
1268            - xulrunner <unfixed> (embed)
1269            - xmame 0.106-2.1 (embed)
1270            NOTE: Might be fixed earlier. Lenny version recorded.
1271            - apache2 2.2 (embed)
1272            - texlive-bin <not-affected> (Embedded code not compiled in)
1273            - vnc4 <unfixed> (embed)
1274            - xotcl 1.6.6-1 (embed)
1275            - chromium-browser 5.0.375.29~r46008-3
1276    
1277    xerces-c
1278            - xerces-c2 <unfixed> (old-version)
1279            - xerces27 <removed> (old-version)
1280    
1281    md5 (RSA's version; not the gnu version provided by coreutils)
1282            - w3c-libwww <removed> (embed; bug #551942)
1283            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1284    
1285    libparagui1.1
1286            - asc <unfixable> (fork)
1287    
1288    enet
1289            - sauerbraten <unfixed> (embed; #497194)
1290    
1291    eglibc
1292            - glibc <removed> (old-version)
1293            - mksh <unfixable> (static)
1294              NOTE: /bin/mksh-static only, and only on some arches (others use dietlibc)
1295    
1296    galib
1297            - gamera 3.2.3-1 (embed)
1298    
1299    configobj
1300            - bzr 2.1.0~rc2-1 (embed; bug #555336)
1301            - elisa <unfixed> (embed; bug #555337)
1302            - gaupol <unfixed> (embed; bug #555338)
1303            - ipython <unfixed> (embed; bug #555339)
1304            - pida <unfixed> (embed; bug #555340)
1305            - psychopy <unfixed> (embed; bug #555341)
1306            - rest2web <unfixed> (embed; bug #555342)
1307            - auth2db <unknown> (embed)
1308            - dynagen <unknown> (embed)
1309            - iceweasel <unknown> (embed)
1310            - sabnzbdplus <unknown> (embed)
1311            - xulrunner <unknown> (embed)
1312            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1313    
1314    python-clientform
1315            - bibus <unfixed> (embed; bug #555332)
1316            - zope2.10 <unfixed> (embed; bug #555333)
1317            - zope2.11 <removed> (embed; bug #555334)
1318            - python-mechanize <unknown> (embed)
1319            - twill <unknown> (embed)
1320    
1321    python-mechanize
1322            - zope2.10 <unfixed> (embed; bug #555337)
1323            - zope2.11 <removed> (embed; bug #555338)
1324            - twill <unknown> (embed; bug #555339)
1325    
1326    pexpect
1327            - duplicity 0.6.06-1 (embed; bug #555361)
1328            - hplip <unfixed> (embed; bug #555362)
1329            - smart <unfixed> (embed; bug #555363)
1330    
1331    pyparsing
1332            - bauble <unfixed> (embed; bug #555366)
1333            - boa-constructor 0.6.1-8 (embed; bug #555367)
1334            - calibre <unfixed> (embed; bug #555368)
1335            - matplotlib <unfixed> (embed; bug #531024)
1336            - zhpy 1.7.3.1-1 (embed; bug #555370)
1337            - polybori <unknown> (embed)
1338            - python-whoosh <unknown> (embed)
1339            - twill <unknown> (embed)
1340            - zope-textindexng3 <unknown> (embed)
1341    
1342    python-pysqlite2
1343            - python2.4 <unfixed> (embed; bug #553403)
1344            - python2.5 <unfixed> (embed; bug #553403)
1345    
1346    celementtree
1347            - python2.5 <unfixed> (embed)
1348            - smart <unfixed> (embed)
1349    
1350    elementtree
1351            - python2.5 <unfixed> (embed)
1352            - python2.6 <unfixed> (embed)
1353            - bzr 2.1.0~rc2-1 (embed; bug #555343)
1354            - gedit 2.28.2-1 (embed; bug #555344)
1355            - smart <unfixed> (embed)
1356            - solfege <unfixed> (embed; bug #555345)
1357            - w3af <unfixed> (embed; bug #555346)
1358            - python-qt4 <unknown> (embed)
1359            - sphinx <unknown> (embed)
1360            - python-nltk <itp> (embed)
1361    
1362    python2.5
1363            - python2.4 <unfixed> (old-version)
1364            - jython <unfixed> (embed)
1365            NOTE: embeds many stdlib modules
1366            - python-django <unfixed> (embed; bug #555419)
1367            NOTE: embeds stdlib modules: doctest, decimal
1368            - gamera 3.2.3-1 (embed)
1369            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1370            - boa-constructor <unfixed> (embed; bug #555426)
1371            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1372            - nicotine <unfixed> (embed; bug #555427)
1373            NOTE: embeds stdlib modules: ConfigParser
1374            - museek+ <unfixed> (embed; bug #555428)
1375            NOTE: embeds stdlib modules: ConfigParser
1376            - vegastrike-data <removed> (embed)
1377            NOTE: embeds many stdlib modules
1378            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1379            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1380            - config-manager <unfixed> (embed; bug #555423)
1381            NOTE: embeds stdlib modules: optparse
1382            - jhbuild 2.28.0-1 (embed; bug #555421)
1383            NOTE: embeds stdlib modules: optparse, subprocess
1384            - smart <unfixed> (embed; bug #555432)
1385            NOTE: embeds stdlib modules: optparse
1386            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1387            NOTE: embeds stdlib modules: doctest
1388            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1389            NOTE: embeds stdlib modules: doctest
1390            - distribute <unfixed> (embed)
1391            NOTE: embeds stdlib modules: doctest
1392            - python-setuptools <unfixed> (embed; bug #555435)
1393            NOTE: embeds stdlib modules: doctest
1394            - zope.testing <unfixed> (embed; bug #555436)
1395            NOTE: embeds stdlib modules: doctest
1396            - translate-toolkit <unfixed> (embed; bug #555422)
1397            NOTE: embeds stdlib modules: textwrap, contextlib
1398            - libtpclient-py <unfixed> (embed; bug #555424)
1399            NOTE: embeds stdlib modules: subprocess
1400            - grass <unfixed> (embed; bug #555425)
1401            NOTE: embeds stdlib modules: subprocess
1402            - coherence <unfixed> (embed; bug #555429)
1403            NOTE: embeds stdlib modules: uuid
1404            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1405            NOTE: embeds stdlib modules: uuid
1406            - setroubleshoot <removed> (embed; bug #555431)
1407            NOTE: embeds stdlib modules: uuid
1408            - linkchecker <unfixed> (embed; bug #555414)
1409            NOTE: embeds msgfmt.py script
1410            - imdbpy <unfixed> (embed)
1411            NOTE: embeds msgfmt.py script
1412            - kiwi <unfixed> (embed)
1413            NOTE: embeds msgfmt.py script
1414            - moin <unfixed> (embed)
1415            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1416            - plone3 <removed> (embed)
1417            NOTE: embeds msgfmt.py script
1418            - roundup <unfixed> (embed)
1419            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1420            - rednotebook <unfixed> (embed; bug #555415)
1421            NOTE: embeds msgfmt.py script
1422            - turbogears <unfixed> (embed)
1423            NOTE: embeds msgfmt.py script
1424            - elisa <unfixed> (embed)
1425            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1426            - calibre <unfixed> (embed)
1427            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1428            - mailman 1:2.1.13-1 (embed; #555416)
1429            NOTE: embeds msgfmt.py script
1430            - python-docutils <unknown> (embed)
1431            NOTE: embeds stdlib modules: optparse, textwrap
1432            - python-imaging <unknown> (embed)
1433            NOTE: embeds stdlib modules: doctest
1434            - python-mechanize <unknown> (embed)
1435            NOTE: embeds stdlib modules: doctest
1436            - twill <unknown> (embed)
1437            NOTE: embeds stdlib modules: subprocess
1438            - zeroc-ice <unknown> (embed)
1439            NOTE: embeds stdlib modules: subprocess
1440            - wxwidgets2.8 <unknown> (embed)
1441            NOTE: embeds stdlib modules: subprocess
1442            - cycle <unknown> (embed)
1443            NOTE: embeds msgfmt.py script
1444            - deluge <unknown> (embed)
1445            NOTE: embeds msgfmt.py script
1446            - opendict <unknown> (embed)
1447            NOTE: embeds msgfmt.py script
1448            - openerp-client <unknown> (embed)
1449            NOTE: embeds msgfmt.py script
1450            - rapidsvn <unknown> (embed)
1451            NOTE: embeds msgfmt.py script
1452            - wammu <unknown> (embed)
1453            NOTE: embeds msgfmt.py script
1454            - gaphor <unknown> (embed)
1455            NOTE: embeds msgfmt.py script
1456            - pida <unknown> (embed)
1457            NOTE: embeds msgfmt.py script
1458            - python-formencode <unknown> (embed)
1459            NOTE: embeds msgfmt.py script
1460            - duplicity <unfixed> (embed)
1461            NOTE: embeds stdlib module: urlparse, tarfile
1462            - pygopherd <unfixed> (embed)
1463            NOTE: embeds stdlib module: zipfile
1464    
1465    argparse
1466            - twill <unfixed> (embed; bug #555347)
1467            - ipython <unfixed> (embed; bug #555348)
1468    
1469    coherence
1470            - elisa <unfixed> (embed; bug #555335)
1471    
1472    simpletal
1473            - plastex <unfixed> (embed; bug #555371)
1474    
1475    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1476            - postr <unfixed> (embed)
1477            - elisa <unfixed> (embed)
1478    
1479    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1480            - apertium-tolk <unfixed> (embed)
1481            - ipython <unfixed> (embed)
1482            - virtaal <unfixed> (embed)
1483    
1484    distribute
1485            - setuptools <removed> (old-version)
1486    
1487    rails
1488            - jruby1.2 <removed> (embed) [./bench/rails/*]
1489            NOTE: jruby is in non-free, it probably includes rails too
1490            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1491            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1492            - thin <unfixed> (embed) [./spec/rails_app/*]
1493            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1494            NOTE: be dangerous if developers are naively basing their code off of the examples
1495            NOTE: prototype.js is among the example files
1496    
1497    lucene2 (prototype.js is among the embeds in the following)
1498            - lucene <unfixed> (old-version)
1499            - pylucene <unfixed> (embed)
1500            - libpdfbox-java <unfixed> (embed)
1501            - libfontbox-java <unfixed> (embed)
1502            - libjempbox-java <unfixed> (embed)
1503            - solr <unfixed> (embed)
1504    
1505    unicode-data
1506            - syslinux <unfixed> (embed)
1507            - camomile <unfixed> (embed)
1508            - fribidi <unfixed> (embed)
1509            - m17n-db <unfixed> (embed)
1510            - sbcl <unfixed> (embed)
1511            - heimdal <unfixed> (embed)
1512            - icu <unfixed> (embed)
1513            - icu4j <unfixed> (embed)
1514            - krb5 <unfixed> (embed)
1515            - moodle <unfixed> (embed)
1516            - openldap <unfixed> (embed)
1517            - pike7.6 <unfixed> (embed)
1518            - samba <unfixed> (embed)
1519            - samba4 <unfixed> (embed)
1520            - cmucl <unfixed> (embed)
1521            - typo3-src <unfixed> (embed)
1522            - mauve <unfixed> (embed)
1523            - texlive-bin <unfixed> (embed)
1524            - ypsilon <unfixed> (embed)
1525            - jeuclid <unfixed> (embed)
1526            - charmap.app <unfixed> (embed)
1527            - clisp <unfixed> (embed)
1528            - gnulib <unfixed> (embed)
1529            - opensrs-client <unfixed> (embed)
1530            - saxonb <unfixed> (embed)
1531            - rails <unfixed> (embed)
1532    
1533    feedparser
1534            - rawdog <unfixed> (embed; bug #383422)
1535            - miro <unfixed> (embed; bug #555351)
1536            - calibre <unfixed> (embed; bug #555352)
1537            - freevo <unfixed> (embed; bug #555353)
1538            - pida <unfixed> (embed; bug #555354)
1539            - planet-venus <unfixed> (embed; bug #555355)
1540            - plone3 <removed> (embed; bug #555356)
1541            - exaile 0.2.14+debian-1 (embed)
1542            - screenlets 0.1.2-3 (embed)
1543            NOTE: included twice
1544    
1545    agg:
1546            - matplotlib <unfixed> (embed: bug #377271)
1547            - contextfree <unfixed> (embed)
1548            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1549            - exactimage <unfixed> (embed)
1550            - python-enable <unfixed> (embed)
1551            - mapnik 0.5.1-3 (embed)
1552            NOTE: links statically to agg, but shared library is not available (bug #377271)
1553    
1554    vtk
1555            - paraview <unfixable> (embed; bug #495426)
1556    
1557    txt2tags
1558            - rednotebook <unfixed> (embed)
1559    
1560    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1561            - gajim <unfixed> (embed)
1562            - emesene <unfixed> (embed)
1563            - convirt <unfixed> (embed)
1564            - pida <unfixed> (embed)
1565            - rednotebook <unfixed> (embed)
1566    
1567    horde3 (prototype.js is among the embeds in the following)
1568            - mnemo2 <unfixed> (embed)
1569            - nag2 <unfixed> (embed)
1570            - wordpress <unfixed> (embed)
1571            NOTE: Text_Diff (wp-includes/Text/Diff*)
1572    
1573    cimg
1574            - gmic <unfixed> (embed)
1575    
1576    mootools
1577            - kdenetwork <unfixed> (embed)
1578            - gallery <unfixed> (embed)
1579            - jspwiki <unfixed> (embed)
1580            - vdr-plugin-live <unfixed> (embed)
1581            - perl-doc-html <unfixed> (embed)
1582    
1583  libsndfile:  openldap
1584  ardour          - openldap2.3 <removed> (old-version)
1585    
1586  glibmm2.4:  grub2
1587  ardour          - grub <unfixed> (old-version)
1588    
1589  libgnomecanvasmm2.6:  gnupginterface
1590  ardour          - duplicity <unfixed> (embed)
1591    
1592  libsigc++-2.0:  python-dateutil
1593  ardour          - awn-extras-applets <unfixed> (embed)
1594            - matplotlib <unknown> (embed)
1595    
1596    cups
1597            - cupsys <removed> (old-version)
1598    
1599    yui
1600            - bcfg2 <not-affected> (present in source but not included in any binary files)
1601            - serendipity 1.5.3-1 (embed; bug #557746)
1602            - moodle 1.8.2.dfsg-5 (embed)
1603            - jifty 0.91117-1 (embed; bug #557748)
1604            - webgui 7.7.26-1 (embed)
1605            - loggerhead 1.17-1 (embed)
1606            - otrs2 2.4.7+dfsg1-1 (embed; bug #592146)
1607    
1608    quake3 (vanilla source not packaged in debian)
1609            - openarena <unfixable> (fork)
1610    
1611    quake2 (vanilla source not packaged in debian)
1612            - alien-arena <unfixable> (fork)
1613            - warsow <unfixable> (fork)
1614    
1615    libtheora
1616            - iceweasel <not-affected> (uses xulrunner)
1617            - xulrunner <unfixed> (embed; bug #540959)
1618            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1619            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1620            - iceape <unfixed> (embed; bug #559276)
1621            [etch] - iceape <not-affected> (introduced in iceape 2.0)
1622            [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1623    
1624    dtoa
1625            - bfilter <unfixed> (embed)
1626            - cacao <removed> (embed)
1627            - cdrdao <unfixed> (embed)
1628            - classpath <unfixed> (embed)
1629            - freej <unfixed> (embed)
1630            - iceape <unfixed> (embed)
1631            - iceweasel <unfixed> (embed)
1632            - jscoverage <unfixed> (embed)
1633            - kde4libs <unfixed> (embed)
1634            - kdelibs <unfixed> (embed)
1635            - kompozer <unfixed> (embed)
1636            - libv8 <unfixed> (embed)
1637            - mono <unfixed> (embed)
1638            - newlib <unfixed> (embed)
1639            - nspr <unfixed> (embed)
1640            - php5 <unfixed> (embed)
1641            - polyml <unfixed> (embed)
1642            - qt4-x11 <unfixed> (embed)
1643            - rhino <unfixed> (embed)
1644            NOTE: code translated to Java
1645            - ruby1.8 <unfixed> (embed)
1646            - ruby1.9 <unfixed> (embed)
1647            - ruby1.9.1 <unfixed> (embed)
1648            - sdd <unfixed> (embed)
1649            - sfind <unfixed> (embed)
1650            - star <unfixed> (embed)
1651            - tinymux <unfixed> (embed)
1652            - virtualbox-ose <unfixed> (embed)
1653            - webkit <unfixed> (embed)
1654            - xulrunner <unfixed> (embed)
1655    
1656    ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1657            - firegpg <unfixed> (embed)
1658            - enigmail <unfixed> (embed)
1659    
1660    ptmalloc (not packaged in Debian)
1661            - crystalspace <unfixed> (embed)
1662            - qt4-x11 <unfixed> (embed)
1663    
1664    svgalib
1665            - usplash <unfixed> (embed)
1666    
1667    bogl
1668            - usplash <unfixed> (embed)
1669    
1670    taglist
1671            - usplash <unfixed> (embed)
1672    
1673    portaudio
1674            - audacity <unfixed> (embed; bug #323711)
1675    
1676    nyquist
1677            - audacity <unfixed> (embed)
1678            NOTE: embeds a forked nyquist with support for a shared library
1679    
1680  soundtouch:  vamp-plugin-sdk
1681  ardour          - audacity <unfixed> (embed)
1682    
1683  libmms:  wordpress
1684  xine-lib          - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1685  mimms          - wordpress-mu <removed> (fork)
1686    
1687  FCKeditor: (packaged as fckeditor)  php5
1688  knowledgeroot          - php4 <removed> (old-version)
 moin (452599)  
 karrigell (452598)  
 gforge-plugins-extra (fixed since 4.6.99+svn6225-1)  
1689    
1690    classpath
1691            - libgnucrypto-java <removed> (embed; bug #559788)
1692    
1693    libtool
1694            - apr <unfixed> (static; bug #489625)
1695            NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1696            - arts <unfixed> (embed)
1697            - bochs 2.4.2-1 (embed; bug #560884)
1698            - camserv <unfixed> (embed)
1699            - collectd 4.8.2-1 (embed)
1700            - courier-authlib 0.58-4 (embed)
1701            NOTE: The etch version of courier-authlib was the earliest version checked, might be fixed earlier
1702            - cvsnt 2.5.04.3236-1.2 (embed)
1703            - dico <not-affected> (Uses the system copy of ltdl)
1704            - freeradius 0.1+20010527-1 (embed)
1705            NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1706            - ggobi 2.1.9~20091212-1 (embed)
1707            - glame 2.0.1-4 (embed)
1708            NOTE: The etch version of glame was the earliest version checked, might be fixed earlier
1709            - gnash 0.8.7-2 (embed)
1710            - gnu-smalltalk <unfixed> (embed; bug #566777)
1711            - google-gadgets 0.10.5-0.3 (embed)
1712            NOTE: 0.10.5-0.3 was the earliest version checked, was fixed earlier
1713            - graphicsmagick 1.3.5-6 (embed)
1714            - graphviz 2.8-3 (embed)
1715            NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1716            - guile-1.6 1.6.8-7 (embed)
1717            - hamlib 1.2.11-1 (embed)
1718            - hercules 3.06-1.2 (embed)
1719            - jags 1.0.4-3 (embed; bug #560864)
1720            - kdelibs <unfixed> (embed)
1721            - libannodex <removed> (embed)
1722            - libextractor 0.5.23+dfsg-4 (embed)
1723            - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1724            - libtunepimp 0.5.3-7.3 (embed)
1725            - mp4h 1.3.1-4.1 (embed)
1726            - naim <removed> (embed)
1727            - parser-mysql <unfixed> (embed)
1728            - pinball 0.3.1-11 (embed)
1729            - redland <unfixed> (embed)
1730            - siproxd <unfixed> (embed)
1731            - ski <unfixed> (embed)
1732            - synfig 0.62.00-1 (embed)
1733            - unixodbc 2.2.4-5 (embed)
1734            - xmlsec1 <not-affected> (Doesn't enable dynamic loading of crypto modules)
1735            - clamav 0.95+dfsg-1 (embed)
1736            - imagemagick 6:6.2.3.1-1 (embed)
1737            - hypre 2.4.0b-5 (embed)
1738            - lam <unfixed> (embed)
1739            - openmpi <unfixable> (embed; bug #559386)
1740            - parser <unfixed> (embed)
1741            - pdsh 2.18-5 (embed; bug #560892)
1742            - sbnc 1.2-8 (embed)
1743            - sdcc <unfixed> (embed)
1744            - wml <not-affected> (The embedded ltdl isn't used, instead mp4h is used, see 559841)
1745            - proftpd-dfsg <unfixed> (embed; bug #561748)
1746            - babel 1.4.0.dfsg-5 (embed)
1747            - libprelude 0.9.14-2 (embed)
1748            - heartbeat 2.1.4-7 (embed)
1749            NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1750            NOTE: might've been fixed earlier
1751            - gcc-* <unknown> (embed)
1752    
1753    ocamlgsl
1754            - orpie 1.5.1-7.1 (embed; bug #550058)
1755    
1756    xdotool
1757            - keynav <unfixed> (embed; bug #560103)
1758    
1759    bulletphysics (not packaged; http://www.bulletphysics.org/)
1760            - supertuxkart <unfixed> (embed)
1761            - blender <unfixed> (embed)
1762    
1763  Moodle contains lots of things:  ghostscript
1764  AdoDB          - gs-gpl <removed> (old-version)
 AdoDB-XML Schema  
 ipatlas  
 PHPMailer  
 Smarty  
 htmlArea  
 TinyMCE  
 bennu  
1765    
1766  TinyMCE:  icedove
1767  wordpress          - thunderbird <removed> (old-version)
 moodle  
 knowledgeroot  
 joomla (ITP)  
   
 scintilla:  
 scite  
 qscintilla  
 qscintilla2  
 geany  
   
 libphp-adodb:  
 gallery2  
 phppgadmin  
 egroupware  
 phpwiki  
 ipplan  
 typo3  
 moodle  
 cacti (dependency exists, but internal version is used -- only in sarge, fixed in etch)  
1768    
1769  gzip:  sizzlejs (not packaged in Debian, http://sizzlejs.com/)
1770  linux-kernel (lib/inflate.c)          - jquery <unfixed> (embed)
 klibc (based on linux-kernel gzip code)  
 busybox  
1771    
1772  neon:  sed
1773  cadaver (all, but being worked on: #188381)          - ssed <unfixed> (fork)
 gnome-vfs2 (#395874)  
 litmus (#395875)  
 screem (sarge only)  
 sitecopy (#395876)  
 tla (etch/sid only: #395877)  
1774    
1775  libmodplug:  phpatomlib (http://code.google.com/p/phpatomlib)
1776  gst-plugins-bad0.10          - wordpress <unfixed> (embed)
1777    
1778    Services_JSON (http://pear.php.net/package/Services_JSON)
1779            - wordpress <unfixed> (embed)
1780    
1781    phpass (http://www.openwall.com/phpass/)
1782            - gallery2 <unfixed> (embed)
1783            - wordpress <unfixed> (embed)
1784            - typo3-src <unfixed> (modified-embed)
1785            NOTE: file refers to drupal, maybe there's a copy somewhere there
1786            NOTE: a copyright owner search didn't match anything
1787            - libauthen-passphrase-perl <unfixable> (fork)
1788            NOTE: perl implementation of phpass
1789    
1790    squirrelmail
1791            - wordpress <unfixed> (embed)
1792            NOTE: class-pop3.php
1793    
1794    ezSQL (http://www.woyano.com/jv/ezsql)
1795            - wordpress <unfixable> (fork)
1796            NOTE: wp-db.php
1797    
1798    Diff.php (Clay Loveless' version/killersoft.com)
1799            - php-versioncontrol-svn <unfixed>
1800    
1801    libm (provided by libc)
1802            - spring <unfixed> (embed)
1803            NOTE: embedded by embedded copy of streflop
1804            - aide <unfixed> (static)
1805            - busybox <unfixed> (static)
1806            - mindi-busybox <unfixed> (static)
1807            - qemu <unfixed> (static)
1808            NOTE: qemu-user-static
1809            - tuxonice-userui <unfixed> (static)
1810            - zsh <unfixed> (static)
1811            NOTE: zsh-static
1812            - tripwire <unfixed>
1813    
1814    streflop
1815            - spring <unfixed> (embed)
1816    
1817  libvncserver:  minizip
1818  vino          - spring <unfixed> (embed)
1819    
1820  putty:  oscpack
1821  filezilla          - spring <unfixed> (embed)
1822    
1823  tinyxml (not packaged in Debian):  hpiutil2
1824  filezilla          - spring <unfixed> (embed)
1825    
1826  gv:  p7zip
1827  evince (ps/ tree from gv 3.5.8)          - spring <unfixed> (embed)
 evince-gtk (not packaged in Debian)  
1828    
1829  libXbae:  pythonqt (doesn't seem to be python-qtN, unknown source)
1830  libpawlib2-lesstif package (from Cernlib)          - fontmatrix <unfixed> (embed)
1831            - elmerfem <unfixed> (embed)
1832    
1833  libXaw:  iepngfix (not packaged in Debian; http://www.twinhelix.com/css/iepngfix/)
1834  libpawlib2-lesstif package (from Cernlib)          - docvert <unfixed> (embed)
1835            - jifty <unfixed> (embed)
1836            - kdenetwork <unfixed> (embed)
1837            - mediatomb <unfixed> (embed)
1838            - plastex <unfixed> (embed)
1839            - plone3 <removed> (embed)
1840            - python-chaco <unfixed> (embed)
1841            - python-docutils <unfixed> (embed)
1842            - s5 <unfixed> (embed)
1843            - zope2.10 <unfixed> (embed)
1844            - zope2.11 <removed> (embed)
1845            - cython <not-affcted> (embed)
1846            NOTE: part of documentation, which is not installed into the binary package
1847    
1848  (I plan to deal with the above two cases after Etch release. -- KevinMcCarty)  python-docutils
1849            - zope2.10 <unfixed> (embed)
1850            - zope2.11 <removed> (embed)
1851    
1852  libgd2:  tesseract
1853  graphviz (lib/gd seems to be 2.0.33)          - ocropus <unfixed> (static)
1854    
1855  rar:  antlr
1856  unrar-nonfree          - kdevelop <unfixed> (embed)
1857    
1858  unrar-free: (maybe this code is derived from the original rar, too?)  libxerces2
1859  clamav (seems to be disabled in default config)          - openjdk-6 <unfixed> (embed)
1860    
1861  mplayer (DirectMedia Object loader):  kfreebsd-8
1862  xine-lib (src/libw32dll/)          - kfreebsd-7 <unfixed> (old-version)
1863  vlc (modules/codec/dmo/)          - kfreebsd-6 <removed> (old-version)
1864    
1865  libwpd (WordPerfect converter):  ruby1.9.1
1866  openoffice.org          - ruby1.9 <unfixed> (old-version)
1867            - ruby1.8 <unfixed> (old-version)
1868    
1869  fsplib (http://sourceforge.net/projects/fsp/):  maildrop
1870  gftp (lib/fsplib version 0.3)          - courier <unfixed> (embed) [./maildrop]
1871    
1872  librpcsecgss:  glee
1873  krb5          - warzone2100 <not-affected> (embed)
1874    
1875  jasper:  phing
1876  ghostscript          - symfony <unfixed> (embed)
 gs-gpl  
1877    
1878  libidn:  pake
1879  monotone          - symfony <unfixed> (embed)
1880    
1881  liblua:  propel
1882  monotone          - symfony <unfixed> (embed)
1883    
1884  libbotan:  creole
1885  montone          - symfony <unfixed> (embed)
1886    
1887  NetXX:  hfsutils
1888  monotone          - cdrkit <unfixed> (embed; bug #570187)
1889            NOTE: embeds hfsutils code in genisoimage
1890    
1891  libgc:  cdrkit
1892  mono          - grub2 <unfixed> (embed; bug #570156)
1893            NOTE: genisoimage imported into grub-mkisofs
1894    
1895  lzma:  kdebase-workspace
1896  p7zip          - kdebase <unfixed> (old-version)
1897    
1898  lzo:  file
1899  grub2          - php5 <unfixable> (modified-embed)
1900            [lenny] - php5 <not-affected>
1901    
1902  pax code:  cdb
1903  tar          - php5 <unfixed> (embed)
1904  cpio  
1905    libmbfl (itp: #570708)
1906            - php5 <unfixed> (embed)
1907            NOTE: PHP is actually the current upstream, ITP is of that code
1908    
1909    libonig
1910            - php5 5.3.2-1 (embed)
1911    
1912    xmlrpc-epi
1913            - php5 <unfixed> (embed)
1914    
1915    swt-gtk
1916            - eclipse <unfixed> (embed; bug #538808)
1917    
1918    txt2html
1919            - wml 2.0.11ds2-1 (embed)
1920    
1921    ca-certificates
1922            - nss <not-affected> (certificates are in source, but not included in any of the binary packages)
1923    
1924    openexr
1925            - freeimage <unfixed> (embed)
1926    
1927    libmng
1928            - freeimage <unfixed> (embed)
1929    
1930    openjpeg
1931            - freeimage <unfixed> (embed)
1932    
1933    libjpeg6b
1934            - freeimage <unfixed> (embed)
1935    
1936    libjpeg (don't know what exact version)
1937            - dcmtk <unfixed>
1938            - gdcm <unfixed>
1939            - insighttoolkit <unfixed>
1940            - openarena 0.8.5-5+exp1 (bug #495966)
1941            - outguess <unfixed>
1942            - squeak-vm <unfixed> (embed)
1943            - tremulous <unfixed>
1944            - tuxonice-userui <unfixed> (static)
1945            - fpc <unfixed> (static)
1946            - lazarus <unfixed> (static)
1947            NOTE: inherited from fpc, see #472304
1948            - mseide-msegui <unfixed> (static)
1949            NOTE: inherited from fpc, see #472304
1950            - easymp3gain <unfixed> (static)
1951            NOTE: inherited from fpc, see #472304
1952            - winff <unfixed> (static)
1953            NOTE: inherited from fpc, see #472304
1954            - texlive-bin <not-affected> (included in upstream source as dependency of libgd2, but not built or included in any of the binary packages)
1955    
1956    
1957    lxr
1958            - lxr-cvs <unfixed> (embed)
1959    
1960    libfile-copy-recursive-perl
1961            - r-base <unfixed> (embed; bug #577427)
1962            - r-base-core-ra <unfixed> (embed; bug #577429)
1963    
1964    delimmatch
1965            - r-base <unfixed> (embed; bug #577433)
1966            - r-base-core-ra <unfixed> (embed; bug #577434)
1967    
1968    libsmf (ITP: #572558)
1969            - denemo <unfixed> (embed)
1970            NOTE: http://lists.debian.org/debian-mentors/2010/04/msg00269.html
1971    
1972    libselinux
1973            - dpkg 1.15.6 (static)
1974    
1975    xinha (ITP: #479708)
1976            - horde3 <unfixed>
1977            - serendipity <unfixed>
1978            - openacs <unfixed>
1979            - dotlrn <unfixed>
1980    
1981    dvipng
1982            - texlive-bin <not-affected> (code present in source but not included in the binary packages)
1983    
1984    dvipdfmx
1985            - texlive-bin <unfixed> (embed)
1986            NOTE: this is intentionally part of the package now, and the separate dvipdfmx package has been removed from sid/squeeze
1987    
1988    lcdf-typetools
1989            - texlive-bin 2009-1 (embed)
1990    
1991    tex4ht
1992            - texlive-bin 2009-1 (embed)
1993    
1994    freetype
1995            - texlive-bin 2009-1 (embed)
1996    
1997    freetype2
1998            - texlive-bin 2009-1 (embed)
1999    
2000    silgraphite
2001            - texlive-bin <unfixed> (embed)
2002    
2003    unzip
2004            - texlive-bin 2009-1 (embed)
2005    
2006    jbig2dec
2007            - ghostscript 8.71~dfsg2-1 (embed)
2008    
2009    libxml2
2010            - chromium-browser 5.0.375.29~r46008-1
2011    
2012    protobuf
2013            - chromium-browser 5.0.375.70~r48679-2
2014    
2015    libv8
2016            - chromium-browser 5.0.375.38~r46659-1
2017    
2018    nspr
2019            - chromium-browser 5.0.375.29~r46008-3
2020    
2021    yasm
2022            - chromium-browser 5.0.375.29~r46008-2
2023    
2024    libxslt
2025            - chromium-browser 5.0.375.29~r46008-1
2026    
2027    miniupnpc (not packaged in Debian; ITP bug #444392)
2028            - warzone2100 <unfixed> (embed)
2029    
2030    iniparser (not packaged in Debian; RFP bug #582657)
2031            - warzone2100 <unfixed> (modified-embed)
2032    
2033    pyglet
2034            - sympy <unfixed> (embed; bug #459716)
2035    
2036    mpmath
2037            - sympy <unfixed> (embed; bug #541746)
2038    
2039    openssh
2040            - libpam-ssh <unfixed> (embed; bug #598522)
2041    
2042    curl
2043            - cmake 2.6.0-6 (embed)
2044            NOTE: Might be fixed earlier. Lenny version recorded.
2045            - criticalmass <unfixed> (static; bug #599061)
2046            - wengophone 2.1.0~beta1-svn9983-1 (embed)
2047    
2048    lib3ds
2049            - boson <unfixed> (embed; bug #600900)
2050            - openscenegraph <unfixed> (embed; bug #601181)
2051    
2052    xcftools
2053            - gnome-xcf-thumbnailer <unfixed> (embed)
2054    
2055  t1lib:  simplejson
2056  tetex-bin (links to system t1lib since 2.0.2)          - exaile <unfixed> (embed; bug #604547)
 texlive-bin (links to system t1lib)  
2057    
2058    libasycns
2059            - loudmouth <unfixed> (embed; bug #566143)

Legend:
Removed from v.7629  
changed lines
  Added in v.15644

  ViewVC Help
Powered by ViewVC 1.1.5