/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7385 by nion, Sat Nov 24 13:34:37 2007 UTC revision 15610 by jwilk, Tue Nov 23 12:45:35 2010 UTC
# Line 1  Line 1 
1  This file collects cases, where a source package embeds code from  Embedded code copies
2  other projects, without linking dynamically:  ====================
3    
4  xpdf code: (some use xpdf 2, some xpdf 3)  This file collects source packages that embed code from other projects.
5  gpdf (has been replaced by evince - which uses poppler - in Etch)  This is considered bad for fixing security flaws because the fix needs
6  pdftohtml (has been replaced by poppler-utils from the poppler source package, still in Etch, though)  to be applied in multiple source packages.
7  kdegraphics/kpdf (okular, the kpdf replacement in KDE 4 is using poppler, #436164)  
8  tetex-bin (links to poppler since 3.0-12)  Format:
9  cupsys (uses xpdf-utils, it's still present in the src, though)  <srcpkg> (<optional comment about srcpkg>)
10  poppler          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11  koffice/kword (upstream is working on using poppler, #436163)          NOTE: optional comments about the linkage of the embedding srcpkg
12  libextractor (uses internal pdf decoder since 0.5.12-1)  
13  pdfkit.framework (links to poppler since 0.8-4)  status: version number fixing the embedded copy
14  ipe (only small parts, but with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp)          <unfixed> if the issue is not yet fixed
15            <removed> if the package was removed from the archive
16  silc-toolkit:          <itp> if the package is in the process of being packaged
17  silc-client (uses libsilc and libsilcclient)          <not-affected> if the package does not use the embedded copy
18            <unknown> if the version number can not be determined
19  dietlibc:          <unfixable> for unavoidable cases (e.g., forks that add real value)
20  ccontrol (links statically)  sort: static (linking statically against a lib)
21          embed (embeds a copy of the library into another source package)
22  libiax:        modified-embed (embeds a code copy that differs from upstream code)
23  iaxmodem        fork (a full-blown fork of another source package)
24          old-version (an older version of essentially the same code)
 zlib code: (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  
 dpkg  
 rsync (somehow derived code base)  
 mono  
 mozilla(?)  
 Linux kernels  
 pvpgn (links dynamically since 1.7.8-2)  
 mrtg (links dynamically since 2.12.2-1)  
 rpm  
   
 libbz2:  
 dpkg (statically linked)  
   
 libgadu/ekg:  
 centericq  
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not yet packaged in Debian)  
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki  
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 firefox (to be removed)  
 thunderbird (to be removed)  
 iceweasel  
 iceape  
 icedove  
 xulrunner  
 nvu (no longer in Debian)  
25    
26  xli:  The srcpkg might be some string to identify the code if there is no
27  xloadimage  specific source package.
28    
29  lesstif: (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  Everything up to the next line is ignored.
30  openmotif  ---BEGIN
31  xfree86/xorg (in libxpm)  poppler
32            - pdftohtml <unknown>
33  kerberized apps with BSD origin:          [sarge] - pdftohtml <unfixed>
34  krb4          [etch] - pdftohtml <unfixed>
35  krb5          NOTE: has been replaced by poppler-utils
36  heimdal          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
37            - texlive-base 3.0-12 (embed)
38  grip: (which pkg is the origin?)          - texlive-bin 2007-1 (embed)
39  libcdaudio          - koffice 1:2.0.0-1 (embed; bug #436163)
40  grip          - libextractor 0.5.12-1 (embed)
41  gnome-vfs (vfs2 as well?)          NOTE: libextractor is using its own pdf decoder now
42            - ipe <unfixed> (embed)
43  fudforum:          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44  phpgroupware-fudforum          - ruby-gnome2 <unknown> (embed)
45  egroupware-fudforum (removed from egroupware after sarge)          - pdfedit <unfixed> (embed; bug #510794)
46            - swftools <removed> (embed; bug #551293)
47  cvs:          - xpdf 3.02-9 (fork)
48  gcvs (at least an additional script is included, check if there's more)  
49    pdksh (no longer developed since 1999)
50  pcre:          - mksh <unfixable> (fork)
51  all pythons          - posh <unfixable> (fork)
52  php4 (src included, but Debian package links dynamically)  
53  analog (src included, but Debian package links dynamically)  ppmd
54  libgoffice-1          - libcomplearn-mod-ppmd <unfixed> (fork)
55  vfu (#450754)          NOTE: discussion in #458152
56  tf5 (since 5.0beta7 the Debian package links dynamically)  
57  monotone (including this starting from 0.37)  libevent
58  glib (2.14 series for gregex support, only for udeb, regular packag links dynamic)          - transmission 1.71-1 (embed; bug #529372)
59  apache2 (since 2.0.53-4 uses 040_link_external_pcre patch)          - chromium-browser 5.0.375.29~r46008-1
60  exim4 (since 4.10-0.srh20.12 uses 36_pcre patch to use external pcre)          - dnsproxy <unknown> (embed)
61    
62  tiff:  lrmi
63  wxpythongtk (check, which debian pkg this is in)          - read-edid 2.0.0-1 (embed; bug #495131)
64  older kdegraphics/kpdf releases < 3.3 embedded a copy          - s3switch <unfixed> (embed)
65            - xresprobe <unfixed> (embed)
66  uudeview:          - zhcon <unfixed> (embed)
67  libconvert-uulib-perl  
68    php-htmlpurifier
69  sqlite: (not affected by security vulnerabilities so far)          - mahara 1.2.5-1 (embed)
70  amarok          - knowledgeroot 0.9.9.5-5 (embed)
71  monotone          - moodle <unfixed> (embed)
72  iceweasel  
73    peercast
74  util-linux/mount:          - gnome-peercast <removed> (embed)
75  loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb          [etch] - gnome-peercast <unfixed> (embed)
76    
77  webmin:  silc-toolkit
78  usermin (only in sarge)          - silc-client 1.1~beta6-1 (embed)
79    
80  sylpheed:  icclib
81  sylpheed-claws          - ghostscript <unfixed> (embed)
82            - argyll <unfixed> (embed)
83  phpsysinfo:  
84  egroupware  libusb
85  phpgroupware          - argyll <unfixed> (embed)
86    
87  phpldapadmin:  dietlibc
88  egroupware (removed from egroupware after sarge)          - ccontrol 0.9.1+20071204-1 (static)
89            - mksh <unfixable> (static)
90  chmlib:          NOTE: /bin/mksh-static only, and only on some arches (others use eglibc)
91  kchmviewer (ships the code but links dynamically)  
92    libmikmod
93  libavcodec/libavformat (source: ffmpeg):          - pysol-sound-server <unfixed> (modified-embed)
94  mplayer (#395252)          - sdl-mixer1.2 <unfixed> (embed)
95  xvidcap          TODO: report bug
96  kino (links statically, does not include code)          - uqm 0.6.2.dfsg-8 (embed)
97  vlc (links statically, does not include code)          NOTE: Might be fixed earlier. Lenny version recorded.
98  smilutils (links statically, does not include code)          - black-box 1.4.6-2.2 (embed)
99  motion (links statically, does not include code)          NOTE: Might be fixed earlier. Lenny version recorded.
100  gst-ffmpeg  
101  gstreamer0.10-ffmpeg  libiax
102  xmovie          - iaxmodem <unfixable> (embed; bug #548885)
103    
104    spandsp
105            - iaxmodem <unfixable> (embed; bug #548885)
106    
107    python-paramiko
108            - fabric 0.9.0-2 (embed; bug #561398)
109    
110    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
111            - dpkg 1.15.6 (static)
112            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
113            - rsync <unfixed> (embed)
114            - cherokee <unfixed> (embed)
115            NOTE: somehow derived code base
116            - mono <unfixed> (embed)
117            TODO: check mozilla
118            - Linux kernels <unfixed> (embed)
119            - pvpgn 1.7.8-2 (embed)
120            - mrtg 2.12.2-1 (embed)
121            - rpm <unknown> (embed)
122            NOTE: pinged anibal since when rpm was fixed
123            - tuxcmd-modules <unfixed> (embed)
124            - zsync <unfixed>
125            - tra <unfixed>
126            - sash <unfixed>
127            - nsis <unfixed>
128            - pyfits 1:2.3.1-1
129            - mseide-msegui <unfixed>
130            NOTE: mseide
131            - mirrordir <unfixed>
132            - poco <unfixed>
133            - klibc <unfixed>
134            - emboss <unfixed>
135            - ghostscript <unfixed>
136            - freeimage <unfixed>
137            - clamav <unfixed> (fork)
138            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
139            - tuxonice-userui <unfixed> (static)
140            - plt-scheme <unfixed>
141            - perl <unfixed>
142            - paraview <unfixed>
143            - velvet 0.7.56~nozlibcopy-1
144            - gcvs <unfixed>
145            - dump <unfixed>
146            - aide <unfixed> (static)
147            - dar <unfixed> (static)
148            - avfs <unfixed>
149            - fpc <unfixed>
150            - winff <unfixed>
151            NOTE: inherited from fpc, see #472304
152            - lazarus <unfixed>
153            NOTE: inherited from fpc, see #472304
154            - erlang <unfixed> (embed)
155            - gamera 3.2.3-1 (embed)
156            - python2.4 <unfixed> (embed; bug #553403)
157            - python2.5 <unfixed> (embed; bug #553403)
158            - texlive-bin <unknown> (embed)
159    
160    dulwich
161            - hg-git 0.1.0-1 (embed; bug #541996)
162    
163    libvigraimpex
164            - hugin <unfixed> (embed; bug #542259)
165            - enblend-enfuse <unfixed> (embed; bug #542258)
166            - gamera 3.2.3-1 (embed)
167    
168    libbz2
169            - dpkg 1.15.6 (static)
170            - amd64-libs <unfixed> (static)
171            NOTE: let's call it "static"
172            - dar <unfixed> (static)
173            - dump <unfixed> (static)
174            - unalz 0.64-1 (embed)
175            NOTE: has code, by the maint, to use the system version but links against the internal copy
176            - clamav <unfixed> (embed)
177            NOTE: libclamav/nsis/bzlib*
178            - pristine-tar <unfixable> (modified-embed)
179            NOTE: compression code only, not uncompression
180            - r-base-core-ra 1.2.8 (static)
181            - r-base-core 2.11.1 (static)
182            NOTE: links dynamically in squeeze, statically in lenny
183            - rpm <unfixed> (static)
184            NOTE: lsb-rpm package is statically linked, normal rpm links dynamically
185    
186    libyahoo2
187            - centerim <unfixed> (embed; bug #559783)
188    
189    libmsn
190            - centerim <unfixed> (embed; bug #559783)
191    
192    libgadu
193            - centerim <unfixed> (embed; bug #559783)
194            - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
195            - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
196            - kdenetwork 4:3.3.2-5 (embed)
197            NOTE: from kdenetwork: kopete
198            - ekg 1:1.8~rc0-1 (embed)
199            - kadu 0.6.0.2-3 (embed; bug #504430)
200            - gadu <itp> (embed)
201    
202    xmlrpc (which package is the "origin" of this code?)
203            - drupal <unfixed> (embed)
204            - phpgroupware <unfixed> (embed)
205            - egroupware <unfixed> (embed)
206            - phpwiki <unfixed> (embed)
207            - php4 <removed> (embed)
208            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
209    
210    shtool (affects build-time only)
211            - mysql-ocaml <unfixed> (embed)
212            - php4 <removed> (embed)
213            - php5 <unfixed> (embed)
214    
215  mad MPEG decoding lib:  xulrunner
216  mad          - iceape <unfixed> (embed; bug #561749)
217  xine-lib          - iceweasel 2.0.0.19 (embed)
218            - icedove <unfixed> (embed; bug #561750)
219            - kompozer <unfixed> (embed; bug #532168)
220            - galeon 2.0.2-4 (embed)
221            - epiphany-browser 2.14.3-8 (embed)
222            - conkeror 0.9~git080629-2 (embed)
223            - kazehakase 0.4.2-1 (embed)
224    
225    xli
226            - xloadimage <unfixed> (embed)
227    
228    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
229            - openmotif <unfixed> (embed)
230    
231    libxpm
232            - lesstif2 <unfixed> (embed; bug #575750)
233    
234    kerberized apps with BSD origin
235            - krb4 <removed> (embed)
236            - krb5 <unfixed> (embed)
237            - heimdal <unfixed> (embed)
238    
239    grip (which pkg is the origin?)
240            - libcdaudio <unfixed>
241            - grip <unfixed>
242            - gnome-vfs <unfixed>
243            TODO: check vfs2 as well
244    
245    fudforum
246            [etch] - phpgroupware <unfixed> (embed)
247            NOTE: phpgroupware-fudforum
248            [sarge] - egroupware-fudforum <removed> (embed)
249    
250    libbsd
251            - rdate 1:1.2-3 (embed)
252            - atheme-services <unfixed>
253            - libbsd-arc4random-perl <not-affected> (modified-embed)
254            NOTE: code not used, it links dynamically against libbsd instead
255            - isakmpd <unfixed>
256            - bsdgames <unfixed> (embed)
257            - bsd-mailx <unfixed> (embed)
258            - netcat-openbsd <unfixed> (embed; bug #550611)
259            - openssh <unfixed> (embed)
260            - unworkable <unfixed> (embed)
261            - mksh <unfixed> (modified-embed)
262            NOTE: strlcpy(), only used in /bin/mksh-static on eglibc arches
263            NOTE: FIXME, we should only have one entry: - mksh <not-affected> (modified-embed)
264            NOTE: strlcpy() on dietlibc arches; {g,s}etmode(); both unused
265    
266    cvs
267            - gcvs <unfixed> (embed)
268            NOTE: see cvsunix/src in tarball
269    
270    pcre3
271            - php4 <removed> (embed)
272            - analog 2:5.23-0woody1 (embed)
273            - chicken 3.2.7-2 (embed)
274            NOTE: Might be fixed earlier. Lenny version recorded.
275            - goffice <unfixed> (embed)
276            NOTE: libgoffice-*
277            - hypermail 2.2.0.dfsg-2 (embed)
278            NOTE: Might be fixed earlier. Lenny version recorded.
279            - privoxy 3.0.9-1 (embed)
280            NOTE: Might be fixed earlier. Lenny version recorded.
281            - vfu 4.06-4.1 (embed; bug #450754)
282            - tf5 5.0beta7-1 (embed)
283            - monotone 0.43-1 (embed)
284            NOTE: this only affects versions >= 0.37
285            - glib2.0 2.15.2-1 (embed)
286            - apache2 2.0.53-4 (embed)
287            - exim4 4.10-0.srh20.12 (embed)
288            - yacas <unfixed> (embed)
289            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
290            - gtamsanalyzer.app 0.42-5 (embed)
291            - tin 980117-1 (embed)
292            - kazehakase 0.5.2-1
293            - webkit 1.0.1-1 (embed)
294            - qt4-x11 <unfixed> (embed)
295            NOTE: embedded via webkit copy
296            - erlang <unfixed> (embed)
297            - ssed <unfixed> (embed)
298            - ircd-hybrid <unfixed> (static)
299            - emboss <unfixd>
300            - cherokee <unfixed> (embed)
301            - oftc-hybrid 1.6.9.dfsg-1 (embed)
302            - ratbox-services <unfixed> (embed)
303            - squeak-vm <unfixed> (embed)
304            - tinymux <unfixed> (embed)
305    
306    tiff
307            - wxwindows2.4 2.2.1 (embed)
308            - gamera 3.2.3-1 (embed)
309            - freeimage <unfixed> (embed)
310            - libtk-img <unfixed> (embed)
311            NOTE: there are two copies, one under tiff/ other under libtiff/
312            - gdal <unfixed>
313    
314    uudeview
315            - libconvert-uulib-perl <unfixed> (embed)
316            - pan <unfixed> (embed)
317    
318    sqlite (not affected by security vulnerabilities so far)
319            - amarok <unfixed> (embed)
320            - monotone 0.43-1 (embed)
321            - iceweasel <unfixed> (embed)
322            - heimdal <unfixed> (embed; bug #559616)
323    
324    util-linux/mount
325            - loop-aes-utils <unfixed> (embed)
326            NOTE: contains code from util-linux' mount in the mount-aes-udeb
327    
328    sylpheed
329            - sylpheed-claws <unfixed> (fork)
330    
331    phpsysinfo
332            - egroupware <unfixed> (embed)
333            - phpgroupware <unfixed> (embed)
334    
335    phpldapadmin
336            [sarge] - egroupware <unfixed> (embed)
337            NOTE: removed from egroupware after sarge
338    
339    chmlib
340            - kchmviewer <unknown> (embed)
341    
342    ffmpeg (libavcodec/libavformat)
343            - mplayer 1.0~rc2-14 (embed; bug #395252)
344            - kino 1.0.0-1
345            - vlc <not-affected> (Links dynamically since initial release)
346            - smilutils 0.3.0-10
347            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
348            - motion 3.1.19-1
349            - gstreamer0.10-ffmpeg 0.10.3-2
350            - xmovie <removed> (static)
351            TODO: gimp-gap (potentially using ffmpeg code as well)
352            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
353            - audacity 1.3.7-2 (embed; bug #512278)
354            - chromium-browser <unfixed> (fork)
355    
356    faad2
357            - mplayer 1.0~rc2-20 (embed)
358            - avifile <unfixed> (embed; bug #538750)
359            - ffmpeg-debian <removed> (embed)
360    
361    libmad (MPEG decoding lib)
362            - xine-lib <unfixed> (embed)
363            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
364            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
365    
 libdts:  
366  libdts  libdts
367  xine-lib          - xine-lib <unfixed> (embed)
368    
 flac:  
369  flac  flac
370  xine-lib          - xine-lib <unfixed> (embed)
371    
372  liba52:  liba52
373  a52dec          - a52dec <unfixed> (embed)
374  xine-lib          - xine-lib <unfixed> (embed)
375    
376    mpeg2dec (libmpeg2)
377            - xine-lib <unfixed> (embed)
378    
379    libmpeg3
380            - squeak-vm <unfixed> (embed)
381    
382    libntlm
383            - wget <unfixed> (fork; bug #550436)
384            - curl <unfixed> (fork; bug #550437)
385            - cntlm <unfixed> (fork; bug #550438)
386    
387    uw-imap
388            - pine <unfixed> (embed)
389            - alpine <unfixed> (embed)
390    
391    imagemagick
392            - graphicsmagick <unfixed> (fork)
393    
394    python-urlgrabber
395            - mercurial <unfixed> (embed; bug #531062)
396            - w3af <unfixed> (embed; bug #555372)
397            [experimental] - harvestman <unfixed> (embed; bug #555373)
398    
399    beautifulsoup
400            - python-mechanize <unfixed> (embed; bug #555349)
401            - zope2.11 <removed> (embed; bug #555350)
402            - twill <unknown> (embed)
403    
404    halibut
405            - nsis <unfixed> (fork)
406    
407    libghttp
408            - hotway <unfixed> (embed)
409    
410    libsndfile
411            - ardour 1:2.7.1-1 (embed)
412    
413    glibmm2.4
414            - ardour 1:2.7.1-1 (embed)
415    
416    libgnomecanvasmm2.6
417            - ardour 1:2.7.1-1 (embed)
418    
419    libsigc++-2.0
420            - ardour 1:2.7.1-1 (embed)
421    
422    soundtouch
423            - ardour 1:2.7.1-1 (embed)
424    
425    libmms
426            - xine-lib <unfixed> (embed)
427            - mimms <unfixed> (embed)
428    
429    fckeditor
430            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
431            - moin 1.8.2-2 (embed; bug #452599)
432            - karrigell <removed> (embed; bug #452598)
433            - gforge 4.6.99+svn6225-1 (embed)
434            - request-tracker3.8 <unfixed> (embed)
435            - otrs2 <unfixed> (embed)
436    
437    ipatlas (not packaged in Debian)
438            - moodle <unfixed> (embed; bug #507185)
439    
440    libphp-phpmailer
441            - moodle <unfixed> (embed; bug #507185)
442            - mahara <unfixed> (embed)
443            - symfony <unfixed> (embed; bug #566778)
444            [etch] - phpgroupware <unfixed> (embed)
445            NOTE: phpgroupware-felamimail is only in etch
446            - egroupware <unfixed> (embed; bug #504283)
447            - glpi <unfixed>
448    
449    htmlArea (not packaged in Debian)
450            - moodle <unfixed> (embed)
451    
452    giflib
453            - wine <unfixed> (embed; bug #466181)
454    
455    bennu (not packaged in Debian, http://bennu.sourceforge.net)
456            - moodle <unfixed> (embed)
457    
458    smarty
459            - moodle 1.8.2-2 (embed; bug #471158)
460            - gallery2 2.2.5-2 (embed; bug #471160)
461            - mahara 0.9.2-2 (embed; bug #471201)
462            - gosa 2.4beta1-1 (embed; bug #471200)
463    
464    TinyMCE
465            - wordpress 2.5.1-3 (embed; bug #478257)
466            - moodle <unfixed> (embed; bug #507185)
467            - knowledgeroot <unfixed> (embed)
468            - joomla <itp> (bug #326398)
469            - mahara 1.2.6-1 (embed; #597752)
470    
471    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
472            - scite <unfixed> (embed)
473            - qscintilla <unfixed> (embed)
474            - qscintilla2 <unfixed> (embed)
475            - geany <unfixed> (fork)
476            - anjuta <unfixed> (embed)
477    
478    libphp-adodb
479            - moodle <unfixed> (embed; bug #507185)
480            NOTE: also AdoDB-XML Schema
481            - gallery2 <unfixed> (embed)
482            - phppgadmin <unfixed> (embed)
483            - egroupware <unfixed> (embed)
484            - phpwiki <unfixed> (embed)
485            - torrentflux 2.0beta1-2 (embed)
486            - ipplan <unfixed> (embed)
487            - typo3-src <unfixed> (embed)
488            - cacti <unknown> (embed)
489            [sarge] - cacti <unfixed> (embed)
490            NOTE: dependency exists, but internal version is used
491            - gforge 4.7~rc2-6 (embed)
492            - mahara <unfixed> (embed)
493    
494    gzip
495            - linux-2.6 <unfixed> (embed) [lib/inflate.c]
496            - klibc <unfixed> (embed)
497            NOTE: based on linux-kernel gzip code
498            - busybox <unfixed> (embed)
499            - pristine-tar <unfixed> (modified-embed)
500            NOTE: compression code only, not uncompression
501            - ncompress <unfixed> (old-version)
502    
503    neon
504            - cadaver 0.22.3+debian-1 (embed; bug #188381)
505            - gnome-vfs2 <unfixed> (embed; bug #395874)
506            [etch] - litmus <unfixed> (embed; #395875)
507            - litmus <removed> (embed; #395875)
508            [sarge] - screem <unfixed> (embed)
509            - sitecopy 1:0.16.0-1 (embed; bug #395876)
510            [etch] - tla <unfixed> (embed; bug #395877)
511            [sarge] - tla <unfixed> (embed; bug #395877)
512    
513    libmodplug
514            - gst-plugins-bad0.10 0.10.10.2-1 (embed)
515    
516    libvncserver
517            - vino <unfixed> (embed)
518    
519    putty
520            - filezilla <unfixed> (embed)
521    
522    tinyxml (not packaged in Debian; itp bug #531968)
523            - filezilla <unfixed>
524            - crystalspace <unfixed> (embed)
525            - libwfut <unfixed> (embed)
526            - rarian <unfixed> (embed)
527            - bulletml <unfixed> (embed)
528            - pokerth <unfixed> (embed)
529            - qutecom <unfixed> (embed)
530            - sofa-framework <unfixed> (embed)
531            - yate <unfixed> (embed)
532            - antigrav <unfixed> (embed)
533            - balder2d <unfixed> (embed)
534            - cal3d <unfixed> (embed)
535            - criticalmass <unfixed> (embed)
536            - ember <unfixed> (embed)
537            - epiphany <unfixed> (embed)
538            - gambit <unfixed> (embed)
539            - noiz2sa <unfixed> (embed)
540            - ogre <unfixed> (embed)
541            - opencity <unfixed> (embed)
542            - openmovieeditor <unfixed> (embed)
543            - pouetchess <unfixed> (embed)
544            - tecnoballz <unfixed> (embed)
545            - trigger-rally <unfixed> (embed)
546            - xmoto <unfixed> (embed)
547            - mapnik <unknown> (embed)
548            NOTE: uses a different XML parser by default
549            - rrootage 0.23a-6 <embed>
550            NOTE: links to libbulltetml
551            - boson <unknown> (embed)
552            NOTE: the embedded code is unused
553    
554    gv
555            - evince <unfixed> (embed)
556            NOTE: ps/ tree from gv 3.5.8
557            NOTE: evince-gtk is affected (a component of evince source package)
558    
559    libXbae
560            - paw <unfixed> (embed)
561    
562    libgtkhtml
563            - claws-mail-extra-plugins <unfixed> (fork)
564    
565    libXaw
566            - paw <unfixed> (embed)
567            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
568    
569    libgd2
570            - graphviz <unfixed> (embed)
571            NOTE: lib/gd seems to be 2.0.33
572            - wml 2.0.11ds2-1 (embed)
573            - libwmf <unfixed> (embed)
574            NOTE: derived from gd 1.6.3
575            - plt-scheme <unfixed> (embed; bug #601525)
576            - texlive-bin 2009-1 (embed)
577    
578    rar
579            - unrar-nonfree <unfixed> (embed)
580    
581    unrar-free (maybe this code is derived from the original rar, too?)
582            - clamav <unfixed> (embed)
583            NOTE: seems to be disabled in default config
584    
585    mplayer (DirectMedia Object loader)
586            - xine-lib <unfixed> (embed)
587            NOTE: src/libw32dll/
588            - vlc <unfixed> (embed)
589            NOTE: modules/codec/dmo/
590            - mplayer 1.0~rc2-20 (embed)
591    
592    libwpd (WordPerfect converter)
593            - openoffice.org <unfixed> (embed)
594    
595    fsplib (http://sourceforge.net/projects/fsp/)
596            - gftp <unfixed> (embed)
597            NOTE: lib/fsplib version 0.3
598    
599    sprng
600            - tree-puzzle <unfixed> (embed)
601    
602    librpcsecgss
603            - krb5 <unfixed> (embed)
604    
605    jasper
606            - ghostscript 8.64~dfsg-2 (embed)
607    
608    libiris
609            - psi <unfixed> (embed)
610            - kdenetwork <unfixed> (embed)
611            NOTE: kopete embeds libiris but links dynamically to libidn
612            - kdegames <unfixed> (embed)
613            NOTE: ksirk/kde4
614    
615    libidn
616            - monotone 0.43-1 (embed)
617            - psi <unfixed> (embed)
618            NOTE: psi embeds libiris which embeds libidn
619            - kdegames <unfixed> (embed)
620            NOTE: kdegames/kde4 embeds libiris which embeds libidn
621    
622    lua5.1
623            - monotone 0.43-1 (embed)
624            - nmap 5.00-1 (embed; bug #527997)
625            [lenny] - nmap <unfixed> (embed; bug #527997)
626            - ocropus <unfixed> (embed)
627            - enigma <unfixed> (embed)
628            NOTE: requires lua built with C++
629            - freeciv <unfixed> (embed)
630            - spring <unfixed> (embed)
631    
632    libbotan
633            - monotone 0.43-1 (embed)
634    
635    NetXX
636            - monotone 0.43-1 (embed)
637    
638    libgc
639            - mono <unfixed> (embed)
640    
641    lzma
642            - p7zip <unfixed> (embed)
643            - xz-utils <unfixed> (fork)
644            - r-base <unfixed> (embed)
645            NOTE: lzma support not yet in lenny or in r-base-core-ra 1.2.8
646    
647    lzo
648            - grub2 <unfixed> (embed)
649    
650    yassl
651            - mysql-dfsg-5.0 <unfixed> (embed)
652            - mysql-5.1 <unfixed> (embed)
653    
654    pax code
655            - tar <unfixed> (embed)
656            - cpio <unfixed> (embed)
657    
658    t1lib
659            - tetex-bin 2.0.2-1 (embed)
660            - texlive-bin <unknown> (embed)
661            - grace 5.1.14-2 (embed)
662            NOTE: Might be fixed even earlier
663    
664    guichan
665            - boswars <unfixed> (embed)
666            NOTE: maintainer notified us, working on it
667    
668    tolua
669            - boswars <unfixed> (embed)
670            NOTE: maintainer notified us, working on it
671            NOTE: actually tolua++
672            - ocropus <unfixed> (embed)
673            NOTE: actually tolua++
674            - freeciv <unfixed> (embed)
675            NOTE: actually tolua++
676            - enigma <unfixed> (embed)
677    
678    asio-dev
679            - luxrender <removed> (embed)
680    
 libmpeg2:  
 mpeg2dec  
681  xine-lib  xine-lib
682            - vlc <unfixed> (embed)
683            NOTE: only parts included in modules/access/rtsp
684    
685  curl:  netpbm
686  wget (code for NTLM authentication)          - tcl8.3 <unfixed> (embed)
687            - tcl8.4 <unfixed> (embed)
688            - tcl8.5 <unfixed> (embed)
689            NOTE: generic/tkImgGIF.c
690    
691    tk8.5
692            - tk8.0 <removed> (old-version)
693            - tk8.3 <unfixed> (old-version)
694            - tk8.4 <unfixed> (old-version)
695            - perl-tk <unfixable> (fork)
696    
697    samba
698            - mc 2:4.6.2~git20080311-1 (embed)
699            NOTE: maintainer is aware of this, currently searching a solution
700    
701    plib1.8.4c2
702            - boson <unfixed> (fork)
703            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
704    
705    fribidi
706            - quesoglc 0.7.2-2 (embed)
707    
708    glew
709            - quesoglc <unfixed> (embed; bug #489341)
710            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
711            - trigger 0.5.2.1-2 (embed)
712            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
713            - trigger-rally 0.5.2.1-2 (embed)
714            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
715            - chromium-browser 5.0.375.70~r48679-2
716    
717    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
718            - transcend <unfixed> (embed)
719            - cultivation <unfixed> (embed)
720            - passage <unfixed> (embed)
721            - gravitation <unfixed> (embed)
722    
723  TODO evaluate:  tar
724  gimp-gap (potentially using ffmpeg code as well)          - libarchive <unfixed> (embed)
725            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
726    
727  uw-imap:  cpio
728  pine          - libarchive <unfixed> (embed)
729  alpine          NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
730    
731  imagemagick:  kde4libs
732  graphicsmagick          - kdelibs <unfixable> (old-version)
733    
734  halibut:  webkit
735  nsis          - qt4-x11 <unfixed> (embed; bug #479851)
736            [etch] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
737            - kde4libs <unfixable> (fork)
738            NOTE: kde4lib's khtml and webkit were forked from khtml (this tracking, which seems
739            NOTE: reversed genesis-wise, is used because of so much other stuff in kde4libs)
740            - chromium-browser <unfixed> (fork)
741    
742    ftgl
743            - blender 2.46+dfsg-1 (embed)
744    
745    wv
746            - abiword <unfixed>
747    
748    qemu
749            - kvm <removed> (embed; bug #543159)
750            - qemu-kvm <unfixed> (embed; bug #560853)
751            NOTE: kvm superceded by qemu-kvm, which is just user interface (no modules)
752            - xen-3 3.4.2-2 (embed; bug #560856)
753            - xen-unstable <unfixed> (embed; bug #560856)
754    
755    vgabios
756            - kvm <removed> (embed; bug #489442)
757            - qemu-kvm <unfixed> (embed)
758    
759    bochs
760            - kvm <removed> (embed; bug #489442)
761            - qemu-kvm <unfixed> (embed)
762    
763    speex
764            - vorbis-tools <unfixed> (embed)
765            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
766            - gst-plugins-good0.10 <unfixed> (embed)
767            - xine-lib <unfixed> (embed)
768            - libfishsound <unfixed> (embed)
769            - libannodex <removed> (embed)
770            - opal 3.4.2~dfsg-2 (embed)
771            - mumble 1.2.0~beta1-1 (embed)
772            - vlc <unfixed> (embed)
773            - xmms-speex <unfixed> (embed)
774            - libsdl-sound1.2 <unfixed> (embed)
775            - sweep <unfixed> (embed)
776    
777    libreadline
778            - magic <itp> (old-version)
779    
780    opcode
781            - ode <unfixed> (embed)
782            NOTE: opcode is not a package in debian, it is just embedded
783            NOTE: http://www.codercorner.com/Opcode.htm
784    
785    gimpact
786            - ode <unfixed> (embed)
787            NOTE: gimpact is not a package in debian, it is just embedded
788            NOTE: http://gimpact.sf.net
789    
790    mochikit
791            - mahara <unfixed> (embed)
792            NOTE: they require extra patches, still unmerged upstream
793            - ntop <unfixed> (embed)
794            - coherence 0.6.2-1 (embed)
795            - paste <unfixed> (embed)
796            - turbogears <unfixed> (embed)
797            - plone3 <removed> (embed)
798            - xulrunner <unfixed> (embed)
799            - libjifty-plugin-chart-perl <unfixed> (embed)
800            - sabnzbdplus <unfixed> (embed)
801            - tgmochikit <unfixed> (embed)
802    
803    prototypejs
804            - netbeans-ide 6.0.1+dfsg-2 (embed)
805            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
806            - webcit <unfixed> (embed; bug #555219)
807            - asterisk 1:1.6.2.0~rc3-1 (embed)
808            - libjson-ruby 1.1.4-1 (embed; bug #555224)
809            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
810            - horde3 <unfixed> (embed)
811            - knowledgeroot 0.9.8.5-4 (embed; bug #555230)
812            - mediatomb 0.12.0~svn2018-5 (embed; bug #555233)
813            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
814            - ebug-http <unfixed> (embed; bug #555236)
815            - libaws 2.7-1 (embed; bug #555222)
816            - phpgedview <removed> (embed)
817            - poker-network 1.7.6-1 (embed; bug #555238)
818            - rails 2.1.0-6 (embed)
819            - wordpress 2.5.0-2 (embed; bug #555243)
820            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
821            TODO: search through all of the other zope packages
822            - ampache 3.4.1-2 (embed)
823            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
824            - hobix 0.5~svn20070319-4 (embed; bug #555247)
825            - zabbix 1.6.6-4 (embed; bug #555250)
826            - chora2 2.1.1+debian0-1 (embed; bug #555253)
827            - gollem 1.1.1+debian0-1 (embed; bug # 555254)
828            - jscropperui 1.2.1-1 (embed; bug #555257)
829            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
830            - ingo1 1.2.3+debian0-1 (embed; bug #555261)
831            - kronolith2 2.3.3+debian0-1 (embed; bug #555262)
832            - activeldap 1.2.1-1 (embed)
833            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
834            - mantis 1.1.2+dfsg-1 (embed; bug #555265)
835            - otrs2 2.3.4-6 (embed; bug #555267)
836            - webcalendar 1.2~b1-2 (embed; bug #555269)
837            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
838            - jifty 0.90519-1 (embed; bug #555271)
839            - jquery 1.4-1 (embed; bug #555272)
840            - passenger 2.2.5debian1-1 (embed; bug #555273)
841            - plone3 <removed> (embed; bug #555275)
842            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
843            - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
844            - xulrunner <unfixed> (embed)
845            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
846            - jclicmoodle <unfixed> (embed)
847            - git-cola <unfixed> (embed)
848    
849    gdb
850            - insight <unfixed> (embed)
851    
852    e2fsprogs
853            - ldiskfsprogs <unfixable> (fork)
854    
855    quazip (not packaged in Debian)
856            - qcake <unfixed> (embed)
857            NOTE: starting with upstream version 0.6.4
858    
859    exo
860            - pcmanfm <unfixed> (embed; bug #499677)
861            NOTE: slightly modified source code
862    
863    java
864            - openjdk-6 <unfixed>
865            - sun-java5 <unfixed>
866            - sun-java6 <unfixed>
867    
868    libphp-snoopy
869            - ampache 3.4.1-2 (embed; bug #504169)
870            - gforge 4.6.99+svn6094-2 (embed)
871            - mahara 1.0.5-2 (embed; bug #504170)
872            - pixelpost 1.7.1-5 (embed; bug #504171)
873            - mediamate 0.9.3.6-5 (embed; bug #504172)
874            - opendb <removed> (embed; bug #504173)
875            [etch] - opendb <unfixed> (embed; bug #504173)
876            - wordpress 2.5.1-9 (embed; bug #443948)
877            - moodle <unfixed> (embed; bug #507185)
878            [etch] - phpgroupware <unfixed> (embed)
879            NOTE: phpgroupware-felamimail
880            - magpierss 0.72-3 (embed; bug #431089)
881    
882    jquery
883            - zekr <unfixed> (embed)
884            - wordpress <unknown> (embed)
885            - yocto-reader <unfixed> (embed)
886            - textpattern <unfixed> (embed)
887            - genshi 0.5.1-1 (embed)
888            NOTE: compressed file under examples/ dir
889            - prewikka <unfixed> (embed)
890            - libramaze-ruby <unfixed> (embed)
891            - drupal6 <unfixed> (embed)
892            - b2evolution <unfixed> (embed)
893            - wesnoth <unfixed> (embed)
894    
895    tablesorter (jquery plugin, not packaged yet)
896            - wesnoth <unfixed> (embed)
897    
898    kses
899            - wordpress <unfixed> (embed; bug #504242)
900            NOTE: their copy has all methods renamed to wp_<foo>
901            NOTE: kses isn't in Debian, RFP: #504240
902            - moodle <unfixed> (embed; bug #507185)
903            - egroupware <unfixed> (embed)
904    
905    magpierss
906            - wordpress <unfixed> (embed; bug #504242)
907            - moodle <unfixed>
908    
909    php-gettext
910            - wordpress 2.8.4-1 (embed; bug #504242)
911            - docbookwiki <unfixed> (embed)
912            - knowledgeroot 0.9.9.5-1
913            NOTE: non-free
914    
915    libphp-ixr (name may change, it is the Incutio XML-RPC)
916            - wordpress <unfixed> (embed; bug #504242)
917            NOTE: libphp-ixr isn't in Debian, RFP: #504236
918            - dokuwiki <unfixed> (embed)
919            - textpattern <unfixed> (embed)
920    
921    libphp-cas
922            - glpi <unfixed> (embed)
923            - moodle <unfixed> (embed; bug #505984)
924    
925    scriptaculous (prototype.js is among the embeds in the following)
926            - glpi <unfixed> (embed)
927            - libaws <unfixed> (embed; bug #555222)
928            - op-panel <unfixed> (embed)
929            - symfony <unfixed> (embed)
930            NOTE: maintainer says there are extra incompatible changes required
931            - pixelpost 1.7.1-6 (embed)
932            - webhelpers <unfixed> (embed)
933            - qwik <removed> (embed; bug #555241)
934            - smokeping <unfixed> (embed)
935            - turba2 <unfixed> (embed)
936            - typo3-src 4.2.3-1 (embed)
937            - request-tracker3.6 <unfixed> (embed)
938            - request-tracker3.8 <unfixed> (embed)
939            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
940            - wordpress 2.5.0-2 (embed)
941            - libhtml-prototype-perl 1.48-3 (embed)
942    
943    libmarkdown-php
944            - moodle <unfixed> (embed; bug #507185)
945            - pixelpost 1.7.1-6 (embed)
946    
947    php-openid
948            - wordpress-openid 3.3.2-1 (embed)
949    
950    geshi
951            - dokuwiki 0.0.20080505-3.1 (embed)
952            - pgfouine 1.0-1.1 (embed)
953            - websvn 2.1.0-1 (embed)
954    
955    webcalendar
956            - gforge 4.7~rc2-6 (embed; bug #504758)
957    
958    libical
959            - kdepim <unknown> (fork)
960            NOTE: fixed at some point during 4.0
961            - kdepimlibs 4.2.0-1 (fork)
962            - claws-mail-extra-plugins <unfixed> (fork)
963    
964    harfbuzz
965            - qt4-x11 <unfixed> (embed)
966            - pango1.0 <unfixed> (embed)
967            - fontmatrix <unfixed> (embed)
968    
969    libzip
970            - php5 <unfixable> (modified-embed)
971            - odt2txt <unfixed> (embed; bug #523808)
972    
973    json.php (not packaged; should be replaced with php's built-in functions)
974            - moodle <unfixed>
975            - yui <unfixed>
976            - gallery2 <unfixed>
977            - dokuwiki <unfixed>
978            - typo3-src <unfixed>
979    
980    php-fpdf
981            - tcpdf <itp> (fork)
982            - moodle <unfixed>
983            - phpwiki <unfixed>
984            - egroupware <unfixed>
985            - ldap-account-manager <unfixed> (fork)
986    
987    tcpdf (itp: #495985)
988            - moodle <unfixed>
989            - phpmyadmin <unfixed>
990    
991  libghttp:  typo3
992  hotway          - moodle <unfixed>
993    
994    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
995            - moodle <unfixed>
996            - gosa <unfixed>
997    
998    php-ole (itp: #487558)
999            - moodle <unfixed>
1000    
1001    pieforms (http://www.catalyst.net.nz)
1002            - mahara <unfixed>
1003    
1004    savant2 (http://phpsavant.com)
1005            - egroupware <unfixed>
1006    
1007    rssparser (http://nwow.org)
1008            - egroupware <unfixed>
1009            - phpgroupware <unfixed>
1010    
1011    lcms
1012            - openjdk-6 <unfixed> (fork)
1013            - gimp 2.4.0~rc2-2
1014    
1015    libphp-phplayersmenu
1016            - diogenes <unfixed>
1017            - phpldapadmin <unfixed>
1018    
1019    libphp-pclzip
1020            - docvert <unfixed>
1021            - moodle <unfixed>
1022            - egroupware <unfixed>
1023    
1024    libphp-simplepie
1025            - dokuwiki <unfixed>
1026            - wordpress <unfixed>
1027    
1028    libphp-jpgraph
1029            - egroupware <unfixed>
1030    
1031    php-simpletest
1032            - moodle <unfixed>
1033    
1034    libpng
1035            - doxygen 1.5.6-2 (embed)
1036            NOTE: Might be fixed earlier. Lenny version recorded.
1037            - gdal 1.5.2-3 (embed)
1038            NOTE: Might be fixed earlier. Lenny version recorded.
1039            - iceweasel <not-affected> (uses xulrunner)
1040            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
1041            - iceape 1.0.13~pre080614i-0etch1 (embed)
1042            - libfltk1.1 1.1.9-6 (embed)
1043            NOTE: Might be fixed earlier. Lenny version recorded.
1044            - libtk-img <unfixed> (embed)
1045            - htmldoc 1.8.27-3 (embed)
1046            NOTE: Might be fixed earlier. Lenny version recorded.
1047            - xulrunner 1.9.0.13-1 (embed)
1048            [lenny] - xulrunner 1.9.0.11-0lenny1
1049            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1050            - gamera 3.2.3-1 (embed)
1051            - freeimage <unfixed> (embed)
1052            - syslinux-common <unfixable> (embed)
1053            - tuxonice-userui <unfixed> (static)
1054            - texlive-bin 2007.dfsg.2-1~lenny2 (embed)
1055            NOTE: Might be fixed earlier. Lenny version recorded.
1056            - vice 1.22.dfsg1-0.1 (embed)
1057            NOTE: Might be fixed earlier. Lenny version recorded.
1058            - visualboyadvance 1.8.0-4 (embed)
1059            NOTE: Might be fixed earlier. Lenny version recorded.
1060    
1061    irssi
1062            - silc-client <unfixed> (embed)
1063            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
1064    
1065    extc
1066            - mtasc <unfixed> (embed)
1067            - haxe <unfixed> (embed)
1068    
1069    swflib
1070            - mtasc <unfixed> (embed)
1071            - haxe <unfixed> (embed)
1072    
1073    libitext-java
1074            - bouncycastle 2.1.4-1 (embed)
1075    
1076    python-ply
1077            - pyke <unfixed> (embed; bug #555363)
1078            - pywbem 0.7.0-4 (embed; bug #555364)
1079            - sepolgen <unfixed> (embed; bug #555365)
1080            - zope-textindexng3 <unknown> (embed)
1081            - iceweasel <not-affected> (uses xulrunner)
1082            - xulrunner <unknown> (embed)
1083            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
1084    
1085    libdumbnet (libdnet upstream)
1086            - nmap <unfixed> (fork)
1087    
1088    gcc-4.4
1089            - gcc-mingw32 <unfixed> (embed)
1090    
1091    camlimages
1092            - advi <unfixed> (static; bug #550441)
1093    
1094    memcached
1095            - memcachedb <unfixed> (embed)
1096    
1097    yajl
1098            - argyll <unfixed> (embed; bug #544223)
1099            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
1100    
1101    nusoap
1102            - gforge 4.8.2-1 (embed)
1103            - ampache <unfixed> (embed)
1104            - poker-network <unfixed> (embed)
1105            - moodle <unfixed> (embed)
1106            NOTE: code is not used when running under php5 and soap is enabled
1107            - phpwiki <unfixed> (embed)
1108            - gallery2 <unfixed> (embed)
1109            - typo3-src <unfixed> (embed)
1110            - phpgacl 3.3.7-7 (embed)
1111            - mantis 1.1.8+dfsg-1 (embed)
1112    
1113    libept
1114            - adept <unfixed> (embed; bug #540649)
1115    
1116    libvorbis
1117            - iceweasel <not-affected> (uses xulrunner)
1118            - xulrunner <unfixed> (embed; bug #540959)
1119            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1120            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1121            - iceape <unfixed> (embed)
1122            [etch] - iceape <not-affected> (introduced in 2.0)
1123            [lenny] - iceape <not-affected> (introduced in 2.0)
1124    
1125    cairo
1126            - iceweasel <not-affected> (uses xulrunner)
1127            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1128    
1129    liboggz
1130            - iceweasel <not-affected> (uses xulrunner)
1131            - xulrunner <unfixed> (embed; bug #540959)
1132            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1133            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1134            - iceape <unfixed> (embed)
1135            [etch] - iceape <not-affected> (introduced in 2.0)
1136            [lenny] - iceape <not-affected> (introduced in 2.0)
1137    
1138    liboggplay
1139            - iceweasel <not-affected> (uses xulrunner)
1140            - xulrunner <unfixed> (embed; bug #540959)
1141            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1142            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1143            - iceape <unfixed> (embed)
1144            [etch] - iceape <not-affected> (introduced in 2.0)
1145            [lenny] - iceape <not-affected> (introduced in 2.0)
1146    
1147    php-net-dnsbl
1148            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1149    
1150    php-onyx-rss
1151            - serendipity <unfixed> (embed; bug #541740; wontfix: only one script, own package is overkill, appears not to be duplicated in Debian)
1152    
1153    php-text-wiki
1154            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1155    
1156    php-xml-rpc
1157            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1158    
1159    polarssl (does not have a shared library)
1160            - pdkim <itp> (embed; bug #543150)
1161            - xyssl <unfixed> (old-version)
1162    
1163    pidgin (libpurple)
1164            - gaim <removed> (old-version)
1165            - qutecom 2.2~rc3.hg396~dfsg1-6 (embed; bug #559785)
1166            - wengophone <unfixed> (embed; bug #601425)
1167    
1168    icu
1169            - webkit 1.0.1-1 (embed; bug #547214)
1170            - texlive-bin <unfixed> (fork)
1171            NOTE: texlive upstream working with icu upstream to merge their changes
1172            - chromium-browser 5.0.375.29~r46008-3
1173    
1174    cyrus-imapd-2.2
1175            - kolab-cyrus-imapd <unfixed> (fork)
1176            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1177    
1178    python-cxx-dev
1179            - freecad 0.9.2646.3-1 (embed; bug #547936)
1180    
1181    zipios++
1182            - freecad 0.9.2646.3-1 (embed; bug #547941)
1183            - enigma 0.92.3-3 (embed)
1184            NOTE: likely fixed earlier, marking etch's version as fixed
1185    
1186    linux-2.6
1187            - kvm <removed> (embed; bug #549973) [./kernel/*]
1188            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1189            - kernel-source-2.6.8 <removed> (old-version)
1190            - kernel-source-2.4.27 <removed> (old-version)
1191            - kernel-source-2.4.24 <removed> (old-version)
1192            - kernel-source-2.2.25 <removed> (old-version)
1193            - kernel-source-2.2.20 <removed> (old-version)
1194    
1195    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1196            - kvm <removed> (embed) [./libfdt/*]
1197            - qemu-kvm <unfixed> (embed) [./libfdt/*]
1198    
1199    qweb (not packaged)
1200            - ajaxterm <unfixed>
1201    
1202    opensaml2
1203            - opensaml <removed> (old-version)
1204    
1205    shibboleth-sp2
1206            - shibboleth-sp <removed> (old-version)
1207    
1208    tuxonice-userui
1209            - suspend2-userui <removed> (old-version)
1210    
1211    expat
1212            - w3c-libwww <removed> (embed; bug #551941)
1213            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1214            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1215            - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1216            - python2.4 <unfixable> (embed; bug #553403)
1217            - python2.7 2.7-6 (embed)
1218            - mcabber 0.10.0-1 (low; bug #601053)
1219            - python-4suite <unfixed> (embed; bug #516935)
1220            - wxwindows2.4 <removed> (embed)
1221            - wxwidgets2.6 2.6.3.2.2-4 (embed)
1222            - wxwidgets2.8 2.8.10.1-2 (embed)
1223            - albert <unfixed> (embed; bug #600974)
1224            - celementtree 1.0.5-8 (embed)
1225            NOTE: Maybe that was fixed even earlier
1226            - centerim <unfixed> (embed; bug #559783)
1227            - audacity 1.3.2-1 (embed)
1228            - matanza <unfixed> (embed)
1229            - tdom 0.8.3~20080525-1 (embed)
1230            - udunits 2.1.8-4 (embed)
1231            - apr-util 1.2 (embed)
1232            - ayttm <unfxed> (embed; bug #561006)
1233            - cableswig <unfixed> (embed)
1234            - cadaver <unfixed> (embed)
1235            - cmake 2.6.0-6 (embed)
1236            - coin3 <unfixed> (embed)
1237            - cvsnt 2.5.03.2382-3.3+lenny1 (embed)
1238            NOTE: Might be fixed earlier. Lenny version recorded.
1239            - dasher 4.7.3-1 (embed)
1240            NOTE: Might be fixed earlier. Lenny version recorded.
1241            - gdcm 2.0.14-2 (embed)
1242            - ghostscript 8.71~dfsg-2 (embed)
1243            - grmonitor <removed> (embed)
1244            - iceape <unfixed> (embed)
1245            - insighttoolkit 3.16.0-1 (embed)
1246            NOTE: insighttoolkit might've been fixed earlier
1247            - jabber 1.4.3-3.4 (embed)
1248            NOTE: Might be fixed earlier. Lenny version recorded.
1249            - libparagui1.1 1.0.2-1 (embed)
1250            - libspiff1 0.8.3-1 (embed)
1251            NOTE: Might be fixed earlier. Lenny version recorded.
1252            - mcabber <unfixed> (embed; bug #601053)
1253            - paraview 3.6.2-1 (embed)
1254            - poco 1.3.6p1-1 (embed)
1255            - scorched3d 41.3dfsg-1+b1 (embed)
1256            NOTE: Might be fixed earlier. Lenny version recorded.
1257            - simgear <unfixed> (embed)
1258            - sitecopy 1:0.16.0-1
1259            - smart <unfixed> (embed)
1260            NOTE: smart embeds celementree, and it includes expat
1261            - swish-e <not-affected> (Linked against libxml, which is used instead)
1262            - tla 1.3.5+dfsg-15 (embed)
1263            - vtk 4.1.20030227-1 (embed)
1264            - wbxml2 <not-affected> (expat code is only used on Mac OS X, see #560941)
1265            - xmlrpc-c <unfixed> (embed)
1266            - iceweasel <unfixed> (embed)
1267            - kompozer <unfixed> (embed)
1268            - vxl 1.13.0-2 (embed)
1269            - xulrunner <unfixed> (embed)
1270            - xmame 0.106-2.1 (embed)
1271            NOTE: Might be fixed earlier. Lenny version recorded.
1272            - apache2 2.2 (embed)
1273            - texlive-bin <not-affected> (Embedded code not compiled in)
1274            - vnc4 <unfixed> (embed)
1275            - xotcl 1.6.6-1 (embed)
1276            - chromium-browser 5.0.375.29~r46008-3
1277    
1278    xerces-c
1279            - xerces-c2 <unfixed> (old-version)
1280            - xerces27 <removed> (old-version)
1281    
1282    md5 (RSA's version; not the gnu version provided by coreutils)
1283            - w3c-libwww <removed> (embed; bug #551942)
1284            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1285    
1286    libparagui1.1
1287            - asc <unfixable> (fork)
1288    
1289    enet
1290            - sauerbraten <unfixed> (embed; #497194)
1291    
1292    eglibc
1293            - glibc <removed> (old-version)
1294            - mksh <unfixable> (static)
1295              NOTE: /bin/mksh-static only, and only on some arches (others use dietlibc)
1296    
1297    galib
1298            - gamera 3.2.3-1 (embed)
1299    
1300    configobj
1301            - bzr 2.1.0~rc2-1 (embed; bug #555336)
1302            - elisa <unfixed> (embed; bug #555337)
1303            - gaupol <unfixed> (embed; bug #555338)
1304            - ipython <unfixed> (embed; bug #555339)
1305            - pida <unfixed> (embed; bug #555340)
1306            - psychopy <unfixed> (embed; bug #555341)
1307            - rest2web <unfixed> (embed; bug #555342)
1308            - auth2db <unknown> (embed)
1309            - dynagen <unknown> (embed)
1310            - iceweasel <unknown> (embed)
1311            - sabnzbdplus <unknown> (embed)
1312            - xulrunner <unknown> (embed)
1313            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1314    
1315    python-clientform
1316            - bibus <unfixed> (embed; bug #555332)
1317            - zope2.10 <unfixed> (embed; bug #555333)
1318            - zope2.11 <removed> (embed; bug #555334)
1319            - python-mechanize <unknown> (embed)
1320            - twill <unknown> (embed)
1321    
1322    python-mechanize
1323            - zope2.10 <unfixed> (embed; bug #555337)
1324            - zope2.11 <removed> (embed; bug #555338)
1325            - twill <unknown> (embed; bug #555339)
1326    
1327    pexpect
1328            - duplicity 0.6.06-1 (embed; bug #555361)
1329            - hplip <unfixed> (embed; bug #555362)
1330            - smart <unfixed> (embed; bug #555363)
1331    
1332    pyparsing
1333            - bauble <unfixed> (embed; bug #555366)
1334            - boa-constructor 0.6.1-8 (embed; bug #555367)
1335            - calibre <unfixed> (embed; bug #555368)
1336            - matplotlib <unfixed> (embed; bug #531024)
1337            - zhpy 1.7.3.1-1 (embed; bug #555370)
1338            - polybori <unknown> (embed)
1339            - python-whoosh <unknown> (embed)
1340            - twill <unknown> (embed)
1341            - zope-textindexng3 <unknown> (embed)
1342    
1343    python-pysqlite2
1344            - python2.4 <unfixed> (embed; bug #553403)
1345            - python2.5 <unfixed> (embed; bug #553403)
1346    
1347    celementtree
1348            - python2.5 <unfixed> (embed)
1349            - smart <unfixed> (embed)
1350    
1351    elementtree
1352            - python2.5 <unfixed> (embed)
1353            - python2.6 <unfixed> (embed)
1354            - bzr 2.1.0~rc2-1 (embed; bug #555343)
1355            - gedit 2.28.2-1 (embed; bug #555344)
1356            - smart <unfixed> (embed)
1357            - solfege <unfixed> (embed; bug #555345)
1358            - w3af <unfixed> (embed; bug #555346)
1359            - python-qt4 <unknown> (embed)
1360            - sphinx <unknown> (embed)
1361            - python-nltk <itp> (embed)
1362    
1363    python2.5
1364            - python2.4 <unfixed> (old-version)
1365            - jython <unfixed> (embed)
1366            NOTE: embeds many stdlib modules
1367            - python-django <unfixed> (embed; bug #555419)
1368            NOTE: embeds stdlib modules: doctest, decimal
1369            - gamera 3.2.3-1 (embed)
1370            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1371            - boa-constructor <unfixed> (embed; bug #555426)
1372            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1373            - nicotine <unfixed> (embed; bug #555427)
1374            NOTE: embeds stdlib modules: ConfigParser
1375            - museek+ <unfixed> (embed; bug #555428)
1376            NOTE: embeds stdlib modules: ConfigParser
1377            - vegastrike-data <removed> (embed)
1378            NOTE: embeds many stdlib modules
1379            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1380            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1381            - config-manager <unfixed> (embed; bug #555423)
1382            NOTE: embeds stdlib modules: optparse
1383            - jhbuild 2.28.0-1 (embed; bug #555421)
1384            NOTE: embeds stdlib modules: optparse, subprocess
1385            - smart <unfixed> (embed; bug #555432)
1386            NOTE: embeds stdlib modules: optparse
1387            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1388            NOTE: embeds stdlib modules: doctest
1389            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1390            NOTE: embeds stdlib modules: doctest
1391            - distribute <unfixed> (embed)
1392            NOTE: embeds stdlib modules: doctest
1393            - python-setuptools <unfixed> (embed; bug #555435)
1394            NOTE: embeds stdlib modules: doctest
1395            - zope.testing <unfixed> (embed; bug #555436)
1396            NOTE: embeds stdlib modules: doctest
1397            - translate-toolkit <unfixed> (embed; bug #555422)
1398            NOTE: embeds stdlib modules: textwrap, contextlib
1399            - libtpclient-py <unfixed> (embed; bug #555424)
1400            NOTE: embeds stdlib modules: subprocess
1401            - grass <unfixed> (embed; bug #555425)
1402            NOTE: embeds stdlib modules: subprocess
1403            - coherence <unfixed> (embed; bug #555429)
1404            NOTE: embeds stdlib modules: uuid
1405            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1406            NOTE: embeds stdlib modules: uuid
1407            - setroubleshoot <removed> (embed; bug #555431)
1408            NOTE: embeds stdlib modules: uuid
1409            - linkchecker <unfixed> (embed; bug #555414)
1410            NOTE: embeds msgfmt.py script
1411            - imdbpy <unfixed> (embed)
1412            NOTE: embeds msgfmt.py script
1413            - kiwi <unfixed> (embed)
1414            NOTE: embeds msgfmt.py script
1415            - moin <unfixed> (embed)
1416            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1417            - plone3 <removed> (embed)
1418            NOTE: embeds msgfmt.py script
1419            - roundup <unfixed> (embed)
1420            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1421            - rednotebook <unfixed> (embed; bug #555415)
1422            NOTE: embeds msgfmt.py script
1423            - turbogears <unfixed> (embed)
1424            NOTE: embeds msgfmt.py script
1425            - elisa <unfixed> (embed)
1426            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1427            - calibre <unfixed> (embed)
1428            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1429            - mailman 1:2.1.13-1 (embed; #555416)
1430            NOTE: embeds msgfmt.py script
1431            - python-docutils <unknown> (embed)
1432            NOTE: embeds stdlib modules: optparse, textwrap
1433            - python-imaging <unknown> (embed)
1434            NOTE: embeds stdlib modules: doctest
1435            - python-mechanize <unknown> (embed)
1436            NOTE: embeds stdlib modules: doctest
1437            - twill <unknown> (embed)
1438            NOTE: embeds stdlib modules: subprocess
1439            - zeroc-ice <unknown> (embed)
1440            NOTE: embeds stdlib modules: subprocess
1441            - wxwidgets2.8 <unknown> (embed)
1442            NOTE: embeds stdlib modules: subprocess
1443            - cycle <unknown> (embed)
1444            NOTE: embeds msgfmt.py script
1445            - deluge <unknown> (embed)
1446            NOTE: embeds msgfmt.py script
1447            - opendict <unknown> (embed)
1448            NOTE: embeds msgfmt.py script
1449            - openerp-client <unknown> (embed)
1450            NOTE: embeds msgfmt.py script
1451            - rapidsvn <unknown> (embed)
1452            NOTE: embeds msgfmt.py script
1453            - wammu <unknown> (embed)
1454            NOTE: embeds msgfmt.py script
1455            - gaphor <unknown> (embed)
1456            NOTE: embeds msgfmt.py script
1457            - pida <unknown> (embed)
1458            NOTE: embeds msgfmt.py script
1459            - python-formencode <unknown> (embed)
1460            NOTE: embeds msgfmt.py script
1461            - duplicity <unfixed> (embed)
1462            NOTE: embeds stdlib module: urlparse, tarfile
1463            - pygopherd <unfixed> (embed)
1464            NOTE: embeds stdlib module: zipfile
1465    
1466    argparse
1467            - twill <unfixed> (embed; bug #555347)
1468            - ipython <unfixed> (embed; bug #555348)
1469    
1470    coherence
1471            - elisa <unfixed> (embed; bug #555335)
1472    
1473    simpletal
1474            - plastex <unfixed> (embed; bug #555371)
1475    
1476    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1477            - postr <unfixed> (embed)
1478            - elisa <unfixed> (embed)
1479    
1480    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1481            - apertium-tolk <unfixed> (embed)
1482            - ipython <unfixed> (embed)
1483            - virtaal <unfixed> (embed)
1484    
1485    distribute
1486            - setuptools <removed> (old-version)
1487    
1488    rails
1489            - jruby1.2 <removed> (embed) [./bench/rails/*]
1490            NOTE: jruby is in non-free, it probably includes rails too
1491            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1492            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1493            - thin <unfixed> (embed) [./spec/rails_app/*]
1494            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1495            NOTE: be dangerous if developers are naively basing their code off of the examples
1496            NOTE: prototype.js is among the example files
1497    
1498    lucene2 (prototype.js is among the embeds in the following)
1499            - lucene <unfixed> (old-version)
1500            - pylucene <unfixed> (embed)
1501            - libpdfbox-java <unfixed> (embed)
1502            - libfontbox-java <unfixed> (embed)
1503            - libjempbox-java <unfixed> (embed)
1504            - solr <unfixed> (embed)
1505    
1506    unicode-data
1507            - syslinux <unfixed> (embed)
1508            - camomile <unfixed> (embed)
1509            - fribidi <unfixed> (embed)
1510            - m17n-db <unfixed> (embed)
1511            - sbcl <unfixed> (embed)
1512            - heimdal <unfixed> (embed)
1513            - icu <unfixed> (embed)
1514            - icu4j <unfixed> (embed)
1515            - krb5 <unfixed> (embed)
1516            - moodle <unfixed> (embed)
1517            - openldap <unfixed> (embed)
1518            - pike7.6 <unfixed> (embed)
1519            - samba <unfixed> (embed)
1520            - samba4 <unfixed> (embed)
1521            - cmucl <unfixed> (embed)
1522            - typo3-src <unfixed> (embed)
1523            - mauve <unfixed> (embed)
1524            - texlive-bin <unfixed> (embed)
1525            - ypsilon <unfixed> (embed)
1526            - jeuclid <unfixed> (embed)
1527            - charmap.app <unfixed> (embed)
1528            - clisp <unfixed> (embed)
1529            - gnulib <unfixed> (embed)
1530            - opensrs-client <unfixed> (embed)
1531            - saxonb <unfixed> (embed)
1532            - rails <unfixed> (embed)
1533    
1534    feedparser
1535            - rawdog <unfixed> (embed; bug #383422)
1536            - miro <unfixed> (embed; bug #555351)
1537            - calibre <unfixed> (embed; bug #555352)
1538            - freevo <unfixed> (embed; bug #555353)
1539            - pida <unfixed> (embed; bug #555354)
1540            - planet-venus <unfixed> (embed; bug #555355)
1541            - plone3 <removed> (embed; bug #555356)
1542            - exaile 0.2.14+debian-1 (embed)
1543            - screenlets 0.1.2-3 (embed)
1544            NOTE: included twice
1545    
1546    agg:
1547            - matplotlib <unfixed> (embed: bug #377271)
1548            - contextfree <unfixed> (embed)
1549            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1550            - exactimage <unfixed> (embed)
1551            - python-enable <unfixed> (embed)
1552            - mapnik 0.5.1-3 (embed)
1553            NOTE: links statically to agg, but shared library is not available (bug #377271)
1554    
1555    vtk
1556            - paraview <unfixable> (embed; bug #495426)
1557    
1558    txt2tags
1559            - rednotebook <unfixed> (embed)
1560    
1561    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1562            - gajim <unfixed> (embed)
1563            - emesene <unfixed> (embed)
1564            - convirt <unfixed> (embed)
1565            - pida <unfixed> (embed)
1566            - rednotebook <unfixed> (embed)
1567    
1568    horde3 (prototype.js is among the embeds in the following)
1569            - mnemo2 <unfixed> (embed)
1570            - nag2 <unfixed> (embed)
1571            - wordpress <unfixed> (embed)
1572            NOTE: Text_Diff (wp-includes/Text/Diff*)
1573    
1574    cimg
1575            - gmic <unfixed> (embed)
1576    
1577    mootools
1578            - kdenetwork <unfixed> (embed)
1579            - gallery <unfixed> (embed)
1580            - jspwiki <unfixed> (embed)
1581            - vdr-plugin-live <unfixed> (embed)
1582            - perl-doc-html <unfixed> (embed)
1583    
1584  libsndfile:  openldap
1585  ardour          - openldap2.3 <removed> (old-version)
1586    
1587  glibmm2.4:  grub2
1588  ardour          - grub <unfixed> (old-version)
1589    
1590  libgnomecanvasmm2.6:  gnupginterface
1591  ardour          - duplicity <unfixed> (embed)
1592    
1593  libsigc++-2.0:  python-dateutil
1594  ardour          - awn-extras-applets <unfixed> (embed)
1595            - matplotlib <unknown> (embed)
1596    
1597    cups
1598            - cupsys <removed> (old-version)
1599    
1600    yui
1601            - bcfg2 <not-affected> (present in source but not included in any binary files)
1602            - serendipity 1.5.3-1 (embed; bug #557746)
1603            - moodle 1.8.2.dfsg-5 (embed)
1604            - jifty 0.91117-1 (embed; bug #557748)
1605            - webgui 7.7.26-1 (embed)
1606            - loggerhead 1.17-1 (embed)
1607            - otrs2 2.4.7+dfsg1-1 (embed; bug #592146)
1608    
1609    quake3 (vanilla source not packaged in debian)
1610            - openarena <unfixable> (fork)
1611    
1612    quake2 (vanilla source not packaged in debian)
1613            - alien-arena <unfixable> (fork)
1614            - warsow <unfixable> (fork)
1615    
1616    libtheora
1617            - iceweasel <not-affected> (uses xulrunner)
1618            - xulrunner <unfixed> (embed; bug #540959)
1619            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1620            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1621            - iceape <unfixed> (embed; bug #559276)
1622            [etch] - iceape <not-affected> (introduced in iceape 2.0)
1623            [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1624    
1625    dtoa
1626            - bfilter <unfixed> (embed)
1627            - cacao <removed> (embed)
1628            - cdrdao <unfixed> (embed)
1629            - classpath <unfixed> (embed)
1630            - freej <unfixed> (embed)
1631            - iceape <unfixed> (embed)
1632            - iceweasel <unfixed> (embed)
1633            - jscoverage <unfixed> (embed)
1634            - kde4libs <unfixed> (embed)
1635            - kdelibs <unfixed> (embed)
1636            - kompozer <unfixed> (embed)
1637            - libv8 <unfixed> (embed)
1638            - mono <unfixed> (embed)
1639            - newlib <unfixed> (embed)
1640            - nspr <unfixed> (embed)
1641            - php5 <unfixed> (embed)
1642            - polyml <unfixed> (embed)
1643            - qt4-x11 <unfixed> (embed)
1644            - rhino <unfixed> (embed)
1645            NOTE: code translated to Java
1646            - ruby1.8 <unfixed> (embed)
1647            - ruby1.9 <unfixed> (embed)
1648            - ruby1.9.1 <unfixed> (embed)
1649            - sdd <unfixed> (embed)
1650            - sfind <unfixed> (embed)
1651            - star <unfixed> (embed)
1652            - tinymux <unfixed> (embed)
1653            - virtualbox-ose <unfixed> (embed)
1654            - webkit <unfixed> (embed)
1655            - xulrunner <unfixed> (embed)
1656    
1657    ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1658            - firegpg <unfixed> (embed)
1659            - enigmail <unfixed> (embed)
1660    
1661    ptmalloc (not packaged in Debian)
1662            - crystalspace <unfixed> (embed)
1663            - qt4-x11 <unfixed> (embed)
1664    
1665    svgalib
1666            - usplash <unfixed> (embed)
1667    
1668    bogl
1669            - usplash <unfixed> (embed)
1670    
1671    taglist
1672            - usplash <unfixed> (embed)
1673    
1674    portaudio
1675            - audacity <unfixed> (embed; bug #323711)
1676    
1677    nyquist
1678            - audacity <unfixed> (embed)
1679            NOTE: embeds a forked nyquist with support for a shared library
1680    
1681  soundtouch:  vamp-plugin-sdk
1682  ardour          - audacity <unfixed> (embed)
1683    
1684  libmms:  wordpress
1685  xine-lib          - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1686  mimms          - wordpress-mu <removed> (fork)
1687    
1688  FCKeditor: (packaged as fckeditor)  php5
1689  knowledgeroot          - php4 <removed> (old-version)
 moin (452599)  
 karrigell (452598)  
 gforge-plugins-extra (fixed since 4.6.99+svn6225-1)  
1690    
1691    classpath
1692            - libgnucrypto-java <removed> (embed; bug #559788)
1693    
1694    libtool
1695            - apr <unfixed> (static; bug #489625)
1696            NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1697            - arts <unfixed> (embed)
1698            - bochs 2.4.2-1 (embed; bug #560884)
1699            - camserv <unfixed> (embed)
1700            - collectd 4.8.2-1 (embed)
1701            - courier-authlib 0.58-4 (embed)
1702            NOTE: The etch version of courier-authlib was the earliest version checked, might be fixed earlier
1703            - cvsnt 2.5.04.3236-1.2 (embed)
1704            - dico <not-affected> (Uses the system copy of ltdl)
1705            - freeradius 0.1+20010527-1 (embed)
1706            NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1707            - ggobi 2.1.9~20091212-1 (embed)
1708            - glame 2.0.1-4 (embed)
1709            NOTE: The etch version of glame was the earliest version checked, might be fixed earlier
1710            - gnash 0.8.7-2 (embed)
1711            - gnu-smalltalk <unfixed> (embed; bug #566777)
1712            - google-gadgets 0.10.5-0.3 (embed)
1713            NOTE: 0.10.5-0.3 was the earliest version checked, was fixed earlier
1714            - graphicsmagick 1.3.5-6 (embed)
1715            - graphviz 2.8-3 (embed)
1716            NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1717            - guile-1.6 1.6.8-7 (embed)
1718            - hamlib 1.2.11-1 (embed)
1719            - hercules 3.06-1.2 (embed)
1720            - jags 1.0.4-3 (embed; bug #560864)
1721            - kdelibs <unfixed> (embed)
1722            - libannodex <removed> (embed)
1723            - libextractor 0.5.23+dfsg-4 (embed)
1724            - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1725            - libtunepimp 0.5.3-7.3 (embed)
1726            - mp4h 1.3.1-4.1 (embed)
1727            - naim <removed> (embed)
1728            - parser-mysql <unfixed> (embed)
1729            - pinball 0.3.1-11 (embed)
1730            - redland <unfixed> (embed)
1731            - siproxd <unfixed> (embed)
1732            - ski <unfixed> (embed)
1733            - synfig 0.62.00-1 (embed)
1734            - unixodbc 2.2.4-5 (embed)
1735            - xmlsec1 <not-affected> (Doesn't enable dynamic loading of crypto modules)
1736            - clamav 0.95+dfsg-1 (embed)
1737            - imagemagick 6:6.2.3.1-1 (embed)
1738            - hypre 2.4.0b-5 (embed)
1739            - lam <unfixed> (embed)
1740            - openmpi <unfixable> (embed; bug #559386)
1741            - parser <unfixed> (embed)
1742            - pdsh 2.18-5 (embed; bug #560892)
1743            - sbnc 1.2-8 (embed)
1744            - sdcc <unfixed> (embed)
1745            - wml <not-affected> (The embedded ltdl isn't used, instead mp4h is used, see 559841)
1746            - proftpd-dfsg <unfixed> (embed; bug #561748)
1747            - babel 1.4.0.dfsg-5 (embed)
1748            - libprelude 0.9.14-2 (embed)
1749            - heartbeat 2.1.4-7 (embed)
1750            NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1751            NOTE: might've been fixed earlier
1752            - gcc-* <unknown> (embed)
1753    
1754    ocamlgsl
1755            - orpie 1.5.1-7.1 (embed; bug #550058)
1756    
1757    xdotool
1758            - keynav <unfixed> (embed; bug #560103)
1759    
1760    bulletphysics (not packaged; http://www.bulletphysics.org/)
1761            - supertuxkart <unfixed> (embed)
1762            - blender <unfixed> (embed)
1763    
1764  Moodle contains lots of things:  ghostscript
1765  AdoDB          - gs-gpl <removed> (old-version)
 AdoDB-XML Schema  
 ipatlas  
 PHPMailer  
 Smarty  
 htmlArea  
 TinyMCE  
 bennu  
1766    
1767  TinyMCE:  icedove
1768  wordpress          - thunderbird <removed> (old-version)
 moodle  
 knowledgeroot  
 joomla (ITP)  
   
 scintilla:  
 scite  
 qscintilla  
 qscintilla2  
 geany  
   
 libphp-adodb:  
 gallery2  
 phppgadmin  
 egroupware  
 phpwiki  
 ipplan  
 typo3  
 moodle  
 cacti (dependency exists, but internal version is used -- only in sarge, fixed in etch)  
1769    
1770  gzip:  sizzlejs (not packaged in Debian, http://sizzlejs.com/)
1771  linux-kernel (lib/inflate.c)          - jquery <unfixed> (embed)
 klibc (based on linux-kernel gzip code)  
 busybox  
1772    
1773  neon:  sed
1774  cadaver (all, but being worked on: #188381)          - ssed <unfixed> (fork)
 gnome-vfs2 (#395874)  
 litmus (#395875)  
 screem (sarge only)  
 sitecopy (#395876)  
 tla (etch/sid only: #395877)  
1775    
1776  libmodplug:  phpatomlib (http://code.google.com/p/phpatomlib)
1777  gst-plugins-bad0.10          - wordpress <unfixed> (embed)
1778    
1779    Services_JSON (http://pear.php.net/package/Services_JSON)
1780            - wordpress <unfixed> (embed)
1781    
1782    phpass (http://www.openwall.com/phpass/)
1783            - gallery2 <unfixed> (embed)
1784            - wordpress <unfixed> (embed)
1785            - typo3-src <unfixed> (modified-embed)
1786            NOTE: file refers to drupal, maybe there's a copy somewhere there
1787            NOTE: a copyright owner search didn't match anything
1788            - libauthen-passphrase-perl <unfixable> (fork)
1789            NOTE: perl implementation of phpass
1790    
1791    squirrelmail
1792            - wordpress <unfixed> (embed)
1793            NOTE: class-pop3.php
1794    
1795    ezSQL (http://www.woyano.com/jv/ezsql)
1796            - wordpress <unfixable> (fork)
1797            NOTE: wp-db.php
1798    
1799    Diff.php (Clay Loveless' version/killersoft.com)
1800            - php-versioncontrol-svn <unfixed>
1801    
1802    libm (provided by libc)
1803            - spring <unfixed> (embed)
1804            NOTE: embedded by embedded copy of streflop
1805            - aide <unfixed> (static)
1806            - busybox <unfixed> (static)
1807            - mindi-busybox <unfixed> (static)
1808            - qemu <unfixed> (static)
1809            NOTE: qemu-user-static
1810            - tuxonice-userui <unfixed> (static)
1811            - zsh <unfixed> (static)
1812            NOTE: zsh-static
1813            - tripwire <unfixed>
1814    
1815    streflop
1816            - spring <unfixed> (embed)
1817    
1818  libvncserver:  minizip
1819  vino          - spring <unfixed> (embed)
1820    
1821  putty:  oscpack
1822  filezilla          - spring <unfixed> (embed)
1823    
1824  tinyxml (not packaged in Debian):  hpiutil2
1825  filezilla          - spring <unfixed> (embed)
1826    
1827  gv:  p7zip
1828  evince (ps/ tree from gv 3.5.8)          - spring <unfixed> (embed)
 evince-gtk (not packaged in Debian)  
1829    
1830  libXbae:  pythonqt (doesn't seem to be python-qtN, unknown source)
1831  libpawlib2-lesstif package (from Cernlib)          - fontmatrix <unfixed> (embed)
1832            - elmerfem <unfixed> (embed)
1833    
1834  libXaw:  iepngfix (not packaged in Debian; http://www.twinhelix.com/css/iepngfix/)
1835  libpawlib2-lesstif package (from Cernlib)          - docvert <unfixed> (embed)
1836            - jifty <unfixed> (embed)
1837            - kdenetwork <unfixed> (embed)
1838            - mediatomb <unfixed> (embed)
1839            - plastex <unfixed> (embed)
1840            - plone3 <removed> (embed)
1841            - python-chaco <unfixed> (embed)
1842            - python-docutils <unfixed> (embed)
1843            - s5 <unfixed> (embed)
1844            - zope2.10 <unfixed> (embed)
1845            - zope2.11 <removed> (embed)
1846            - cython <not-affcted> (embed)
1847            NOTE: part of documentation, which is not installed into the binary package
1848    
1849  (I plan to deal with the above two cases after Etch release. -- KevinMcCarty)  python-docutils
1850            - zope2.10 <unfixed> (embed)
1851            - zope2.11 <removed> (embed)
1852    
1853  libgd2:  tesseract
1854  graphviz (lib/gd seems to be 2.0.33)          - ocropus <unfixed> (static)
1855    
1856  rar:  antlr
1857  unrar-nonfree          - kdevelop <unfixed> (embed)
1858    
1859  unrar-free: (maybe this code is derived from the original rar, too?)  libxerces2
1860  clamav (seems to be disabled in default config)          - openjdk-6 <unfixed> (embed)
1861    
1862  mplayer (DirectMedia Object loader):  kfreebsd-8
1863  xine-lib (src/libw32dll/)          - kfreebsd-7 <unfixed> (old-version)
1864  vlc (modules/codec/dmo/)          - kfreebsd-6 <removed> (old-version)
1865    
1866  libwpd (WordPerfect converter):  ruby1.9.1
1867  openoffice.org          - ruby1.9 <unfixed> (old-version)
1868            - ruby1.8 <unfixed> (old-version)
1869    
1870  fsplib (http://sourceforge.net/projects/fsp/):  maildrop
1871  gftp (lib/fsplib version 0.3)          - courier <unfixed> (embed) [./maildrop]
1872    
1873  librpcsecgss:  glee
1874  krb5          - warzone2100 <not-affected> (embed)
1875    
1876  jasper:  phing
1877  ghostscript          - symfony <unfixed> (embed)
 gs-gpl  
1878    
1879  libidn:  pake
1880  monotone          - symfony <unfixed> (embed)
1881    
1882  liblua:  propel
1883  monotone          - symfony <unfixed> (embed)
1884    
1885  libbotan:  creole
1886  montone          - symfony <unfixed> (embed)
1887    
1888  NetXX:  hfsutils
1889  monotone          - cdrkit <unfixed> (embed; bug #570187)
1890            NOTE: embeds hfsutils code in genisoimage
1891    
1892  libgc:  cdrkit
1893  mono          - grub2 <unfixed> (embed; bug #570156)
1894            NOTE: genisoimage imported into grub-mkisofs
1895    
1896  lzma:  kdebase-workspace
1897  p7zip          - kdebase <unfixed> (old-version)
1898    
1899  lzo:  file
1900  grub2          - php5 <unfixable> (modified-embed)
1901            [lenny] - php5 <not-affected>
1902    
1903  pax code:  cdb
1904  tar          - php5 <unfixed> (embed)
1905  cpio  
1906    libmbfl (itp: #570708)
1907            - php5 <unfixed> (embed)
1908            NOTE: PHP is actually the current upstream, ITP is of that code
1909    
1910    libonig
1911            - php5 5.3.2-1 (embed)
1912    
1913    xmlrpc-epi
1914            - php5 <unfixed> (embed)
1915    
1916    swt-gtk
1917            - eclipse <unfixed> (embed; bug #538808)
1918    
1919    txt2html
1920            - wml 2.0.11ds2-1 (embed)
1921    
1922    ca-certificates
1923            - nss <not-affected> (certificates are in source, but not included in any of the binary packages)
1924    
1925    openexr
1926            - freeimage <unfixed> (embed)
1927    
1928    libmng
1929            - freeimage <unfixed> (embed)
1930    
1931    openjpeg
1932            - freeimage <unfixed> (embed)
1933    
1934    libjpeg6b
1935            - freeimage <unfixed> (embed)
1936    
1937    libjpeg (don't know what exact version)
1938            - dcmtk <unfixed>
1939            - gdcm <unfixed>
1940            - insighttoolkit <unfixed>
1941            - openarena 0.8.5-5+exp1 (bug #495966)
1942            - outguess <unfixed>
1943            - squeak-vm <unfixed> (embed)
1944            - tremulous <unfixed>
1945            - tuxonice-userui <unfixed> (static)
1946            - fpc <unfixed> (static)
1947            - lazarus <unfixed> (static)
1948            NOTE: inherited from fpc, see #472304
1949            - mseide-msegui <unfixed> (static)
1950            NOTE: inherited from fpc, see #472304
1951            - easymp3gain <unfixed> (static)
1952            NOTE: inherited from fpc, see #472304
1953            - winff <unfixed> (static)
1954            NOTE: inherited from fpc, see #472304
1955            - texlive-bin <not-affected> (included in upstream source as dependency of libgd2, but not built or included in any of the binary packages)
1956    
1957    
1958    lxr
1959            - lxr-cvs <unfixed> (embed)
1960    
1961    libfile-copy-recursive-perl
1962            - r-base <unfixed> (embed; bug #577427)
1963            - r-base-core-ra <unfixed> (embed; bug #577429)
1964    
1965    delimmatch
1966            - r-base <unfixed> (embed; bug #577433)
1967            - r-base-core-ra <unfixed> (embed; bug #577434)
1968    
1969    libsmf (ITP: #572558)
1970            - denemo <unfixed> (embed)
1971            NOTE: http://lists.debian.org/debian-mentors/2010/04/msg00269.html
1972    
1973    libselinux
1974            - dpkg 1.15.6 (static)
1975    
1976    xinha (ITP: #479708)
1977            - horde3 <unfixed>
1978            - serendipity <unfixed>
1979            - openacs <unfixed>
1980            - dotlrn <unfixed>
1981    
1982    dvipng
1983            - texlive-bin <not-affected> (code present in source but not included in the binary packages)
1984    
1985    dvipdfmx
1986            - texlive-bin <unfixed> (embed)
1987            NOTE: this is intentionally part of the package now, and the separate dvipdfmx package has been removed from sid/squeeze
1988    
1989    lcdf-typetools
1990            - texlive-bin 2009-1 (embed)
1991    
1992    tex4ht
1993            - texlive-bin 2009-1 (embed)
1994    
1995    freetype
1996            - texlive-bin 2009-1 (embed)
1997    
1998    freetype2
1999            - texlive-bin 2009-1 (embed)
2000    
2001    silgraphite
2002            - texlive-bin <unfixed> (embed)
2003    
2004    unzip
2005            - texlive-bin 2009-1 (embed)
2006    
2007    jbig2dec
2008            - ghostscript 8.71~dfsg2-1 (embed)
2009    
2010    libxml2
2011            - chromium-browser 5.0.375.29~r46008-1
2012    
2013    protobuf
2014            - chromium-browser 5.0.375.70~r48679-2
2015    
2016    libv8
2017            - chromium-browser 5.0.375.38~r46659-1
2018    
2019    nspr
2020            - chromium-browser 5.0.375.29~r46008-3
2021    
2022    yasm
2023            - chromium-browser 5.0.375.29~r46008-2
2024    
2025    libxslt
2026            - chromium-browser 5.0.375.29~r46008-1
2027    
2028    miniupnpc (not packaged in Debian; ITP bug #444392)
2029            - warzone2100 <unfixed> (embed)
2030    
2031    iniparser (not packaged in Debian; RFP bug #582657)
2032            - warzone2100 <unfixed> (modified-embed)
2033    
2034    pyglet
2035            - sympy <unfixed> (embed; bug #459716)
2036    
2037    mpmath
2038            - sympy <unfixed> (embed; bug #541746)
2039    
2040    curl
2041            - cmake 2.6.0-6 (embed)
2042            NOTE: Might be fixed earlier. Lenny version recorded.
2043            - criticalmass <unfixed> (static; bug #599061)
2044            - wengophone 2.1.0~beta1-svn9983-1 (embed)
2045    
2046    lib3ds
2047            - boson <unfixed> (embed; bug #600900)
2048            - openscenegraph <unfixed> (embed; bug #601181)
2049    
2050    xcftools
2051            - gnome-xcf-thumbnailer <unfixed> (embed)
2052    
2053    simplejson
2054            - exaile <unfixed> (embed; bug #604547)

Legend:
Removed from v.7385  
changed lines
  Added in v.15610

  ViewVC Help
Powered by ViewVC 1.1.5