/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7700 by jmm-guest, Sun Dec 23 10:58:57 2007 UTC revision 13146 by jwilk-guest, Thu Oct 29 15:43:52 2009 UTC
# Line 1  Line 1 
1  Embedded code copies  Embedded code copies
2  ====================  ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects which is considered bad for fixing security flaws  This is considered bad for fixing security flaws because the fix needs
6  because the fix needs to be applied in multiple source packages.  to be applied in multiple source packages.
7    
8  Format:  Format:
9  <srcpkg> (<optional comment about srcpkg>)  <srcpkg> (<optional comment about srcpkg>)
10          - <embedding srcpkg> <status> (<sort>; bug #<number>)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11          NOTE: optional comments about the linkage of the embedding srcpkg          NOTE: optional comments about the linkage of the embedding srcpkg
12    
13  status: version number fixing the embedded copy, <unfixed>, <removed> or <unknown> if the version number can not be determined  status: version number fixing the embedded copy, <unfixed>, <removed>,
14  sort: static/dynamic          <itp>, <not-affected>, <unknown> if the version number can not
15            be determined, or <unfixable> for unavoidable cases (e.g., forks
16            that add real value)
17    sort: static (linking statically against a lib)
18          embed (embedding a copy of the library into another source package)
19          fork (the package is not just embedding code but it is a fork and
20                thus might share parts of the source code)
21          old-version (the package is an older version of essentially
22                       the same code)
23    
24    The srcpkg might be some string to identify the code if there is no
25    specific source package.
26    
27    Everything up to the next line is ignored.
28    ---BEGIN
29  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
30          - gpdf <removed>          NOTE: Fixed packages link to poppler library unless otherwise noted
         [sarge] - gpdf <unfixed>  
         NOTE: has been replaced by evince in etch  
31          - pdftohtml <unknown>          - pdftohtml <unknown>
32          [sarge] - pdftohtml <unfixed>          [sarge] - pdftohtml <unfixed>
33          [etch] - pdftohtml <unfixed>          [etch] - pdftohtml <unfixed>
34          NOTE: has been replaced by poppler-utils          NOTE: has been replaced by poppler-utils
35          - kdegraphics <unfixed> (static; bug #436164)          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
36          NOTE: the kpdf replacement in KDE 4 is using poppler          - texlive-base 3.0-12 (embed)
37          - tetex-bin 3.0-12 (dynamic)          - texlive-bin 2007-1 (embed)
         NOTE: links to poppler  
         - texlive-bin <unknown> (dynamic)  
         NOTE: links to poppler  
         - koffice <unfixed> (static; bug #436163)  
         - libextractor 0.5.12-1 (static)  
         NOTE: libextractor is using its own pdf decoder  
         - libextractor 0.5.12-1 (dynamic)  
         NOTE: links to poppler  
         - pdfkit.framework 0.8-4 (dynamic)  
38          NOTE: links to poppler          NOTE: links to poppler
39          - ipe <unfixed> (static)          - koffice <unfixed> (embed; bug #436163)
40            - libextractor 0.5.12-1 (embed)
41            NOTE: libextractor is using its own pdf decoder now
42            - ipe <unfixed> (embed)
43          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44          - ruby-gnome2 <unknown> (dynamic)          - ruby-gnome2 <unknown> (embed)
45          NOTE: copy only present in source but links to poppler          NOTE: copy only present in source but links to poppler
46            - pdfedit <unfixed> (embed; bug #510794)
47            - swftools <unfixed> (embed; bug #551293)
48            - poppler <unfixable> (fork)
49    
50    ppmd
51            - libcomplearn-mod-ppmd <unfixed> (fork)
52            NOTE: discussion in #458152
53    
54    libevent
55            - transmission 1.71-1 (embed; bug #529372)
56    
57    lrmi
58            - read-edid 2.0.0-1 (embed; bug #495131)
59    
60    peercast
61            - gnome-peercast <removed> (embed)
62            [etch] - gnome-peercast <unfixed> (embed)
63    
64    silc-toolkit
65            - silc-client 1.1~beta6-1 (embed)
66    
67    icclib
68            - ghostscript <unfixed> (embed)
69            - argyll <unfixed> (embed)
70    
71    dietlibc
72            - ccontrol 0.9.1+20071204-1 (static)
73    
74    libmikmod
75            - sdl-mixer1.2 <unfixed> (embed)
76            TODO: report bug
77    
78    libiax
79            - iaxmodem <unfixable> (embed; bug #548885)
80    
81    spandsp
82            - iaxmodem <unfixable> (embed; bug #548885)
83    
84    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
85            - dpkg <unfixed> (embed)
86            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
87            - rsync <unfixed> (embed)
88            NOTE: somehow derived code base
89            - mono <unfixed> (embed)
90            TODO: check mozilla
91            - Linux kernels <unfixed> (embed)
92            - pvpgn 1.7.8-2 (embed)
93            - mrtg 2.12.2-1 (embed)
94            - rpm <unknown> (embed)
95            NOTE: pinged anibal since when rpm was fixed
96            - tuxcmd-modules <unfixed> (embed)
97            - zsync <unfixed>
98            - tra <unfixed>
99            - sash <unfixed>
100            - nsis <unfixed>
101            - mseide-msegui <unfixed>
102            NOTE: mseide
103            - mirrordir <unfixed>
104            - poco <unfixed>
105            - klibc <unfixed>
106            - ghostscript <unfixed>
107            - freeimage <unfixed>
108            - clamav <unfixed> (fork)
109            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
110            - tuxonice-userui <unfixed>
111            - plt-scheme <unfixed>
112            - perl <unfixed>
113            - paraview <unfixed>
114            - gcvs <unfixed>
115            - dump <unfixed>
116            - aide <unfixed> (static)
117            - dar <unfixed> (static)
118            - avfs <unfixed>
119            - fpc <unfixed>
120            - winff <unfixed>
121            NOTE: inherited from fpc, see #472304
122            - lazarus <unfixed>
123            NOTE: inherited from fpc, see #472304
124            - erlang <unfixed> (embed)
125            - gamera 3.2.3-1 (embed)
126    
127    dulwich
128            - hg-git 0.1.0-1 (embed; bug #541996)
129    
130    libvigraimpex
131            - hugin <unfixed> (embed; bug #542259)
132            - enblend-enfuse <unfixed> (embed; bug #542258)
133            - gamera 3.2.3-1 (embed)
134    
135    libbz2
136            - dpkg <unfixed> (static)
137    
138    libgadu
139            - centericq <unfixed> (embed)
140            - pidgin <unfixed> (embed)
141            NOTE: pidgin links dynamically against libgadu; that should be fixed, then???
142            - kdenetwork 4:3.3.2-5 (embed)
143            NOTE: from kdenetwork: kopete
144            - ekg 1:1.8~rc0-1 (embed)
145            - kadu 0.6.0.2-3 (embed; bug #504430)
146            - gadu <itp> (embed)
147    
148    xmlrpc (which package is the "origin" of this code?)
149            - drupal <unfixed> (embed)
150            - phpgroupware <unfixed> (embed)
151            - egroupware <unfixed> (embed)
152            - phpwiki <unfixed> (embed)
153            - php4 <unfixed> (embed)
154            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
155    
156    shtool (affects build-time only)
157            - mysql-ocaml <unfixed> (embed)
158            - php4 <unfixed> (embed)
159    
160  silc-toolkit:  iceape
161  silc-client (uses libsilc and libsilcclient)          - iceweasel <unfixed> (fork)
162            - icedove <unfixed> (fork)
163            - xulrunner <unfixed> (fork)
164            - kompozer <unfixed> (embed; bug #532168)
165    
166    xli
167            - xloadimage <unfixed> (embed)
168    
169    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
170            - openmotif <unfixed> (embed)
171            - libxpm <unfixed> (embed)
172    
173    kerberized apps with BSD origin
174            - krb4 <removed> (embed)
175            - krb5 <unfixed> (embed)
176            - heimdal <unfixed> (embed)
177    
178    grip (which pkg is the origin?)
179            - libcdaudio <unfixed>
180            - grip <unfixed>
181            - gnome-vfs <unfixed>
182            TODO: check vfs2 as well
183    
184    fudforum
185            [etch] - phpgroupware <unfixed> (embed)
186            NOTE: phpgroupware-fudforum
187            [sarge] - egroupware-fudforum <removed> (embed)
188    
189    libbsd
190            - rdate 1:1.2-3 (embed)
191            - atheme-services <unfixed>
192            - libbsd-arc4random-perl <unfixed>
193            - isakmpd <unfixed>
194    
195    cvs
196            - gcvs <unfixed> (embed)
197            NOTE: see cvsunix/src in tarball
198    
199    pcre
200            - python* <unfixed> (embed)
201            - php4 <unknown> (embed)
202            - analog 2:5.23-0woody1 (embed)
203            - goffice <unfixed> (embed)
204            NOTE: libgoffice-*
205            - vfu 4.06-4.1 (embed; bug #450754)
206            - tf5 5.0beta7-1 (embed)
207            - monotone 0.43-1 (embed)
208            NOTE: this only affects versions >= 0.37
209            - glib2.0 2.15.2-1 (embed)
210            - apache2 2.0.53-4 (embed)
211            - exim4 4.10-0.srh20.12 (embed)
212            - yacas <unfixed> (embed)
213            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
214            - gtamsanalyzer.app 0.42-5 (embed)
215            - tin <unknown> (embed)
216            - kazehakase 0.5.2-1
217            - webkit 1.0.1-1 (embed)
218            - qt4-x11 <unfixed> (embed)
219            NOTE: embedded via webkit copy
220            - erlang <unfixed> (embed)
221    
222    tiff
223            - wxwindows2.4 2.2.1 (embed)
224            - gamera 3.2.3-1 (embed)
225    
226    uudeview
227            - libconvert-uulib-perl <unfixed> (embed)
228            - pan <unfixed> (embed)
229    
230    sqlite (not affected by security vulnerabilities so far)
231            - amarok <unfixed> (embed)
232            - monotone 0.43-1 (embed)
233            - iceweasel <unfixed> (embed)
234    
235    util-linux/mount
236            - loop-aes-utils <unfixed> (embed)
237            NOTE: contains code from util-linux' mount in the mount-aes-udeb
238    
239    sylpheed
240            - sylpheed-claws <unfixed> (fork)
241    
242    phpsysinfo
243            - egroupware <unfixed> (embed)
244            - phpgroupware <unfixed> (embed)
245    
246    phpldapadmin
247            [sarge] - egroupware <unfixed> (embed)
248            NOTE: removed from egroupware after sarge
249    
250    chmlib
251            - kchmviewer <unknown> (embed)
252    
253    ffmpeg (libavcodec/libavformat)
254            - mplayer 1.0~rc2-14 (embed; bug #395252)
255            - kino 1.0.0-1
256            - vlc <not-affected> (Links dynamically since initial release)
257            - smilutils 0.3.0-10
258            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
259            - motion 3.1.19-1
260            - gstreamer0.10-ffmpeg 0.10.3-2
261            - xmovie <removed> (static)
262            TODO: gimp-gap (potentially using ffmpeg code as well)
263            - avifile <unfixed> (embed; bug #538750)
264    
265    faad2
266            - mplayer 1.0~rc2-20 (embed)
267            - avifile <unfixed> (embed; bug #538750)
268    
269    libmad (MPEG decoding lib)
270            - xine-lib <unfixed> (embed)
271            - avifile <unfixed> (embed) [./plugins/libmad/*]
272            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
273    
274  dietlibc:  libdts
275  ccontrol (linked statically until 0.9.1+20071204-1, affects Etch only)          - xine-lib <unfixed> (embed)
276    
277  libiax:  flac
278  iaxmodem          - xine-lib <unfixed> (embed)
279    
280  zlib code: (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  liba52
281  dpkg          - a52dec <unfixed> (embed)
282  rsync (somehow derived code base)          - xine-lib <unfixed> (embed)
 mono  
 mozilla(?)  
 Linux kernels  
 pvpgn (links dynamically since 1.7.8-2)  
 mrtg (links dynamically since 2.12.2-1)  
 rpm  
   
 libbz2:  
 dpkg (statically linked)  
   
 libgadu/ekg:  
 centericq  
 gaim  
 pigdin (links dynamically against libgadu)  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not yet packaged in Debian)  
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 firefox (to be removed)  
 thunderbird (to be removed)  
 iceweasel  
 iceape  
 icedove  
 xulrunner  
 nvu (no longer in Debian)  
   
 xli:  
 xloadimage  
   
 lesstif: (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm)  
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum (removed from egroupware after sarge)  
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 all pythons  
 php4 (src included, but Debian package links dynamically)  
 analog (src included, but Debian package links dynamically)  
 libgoffice-1  
 vfu (removed linking against embedded copy in 4.06-4.1; #450754)  
 tf5 (since 5.0beta7 the Debian package links dynamically)  
 monotone (including this starting from 0.37)  
 glib (2.14 series for gregex support, only for udeb, regular packag links dynamic)  
 apache2 (since 2.0.53-4 uses 040_link_external_pcre patch)  
 exim4 (since 4.10-0.srh20.12 uses 36_pcre patch to use external pcre)  
 yacas (<= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway)  
 gtamsanalyzer.app (links dynamically since 0.42-5)  
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
   
 uudeview:  
 libconvert-uulib-perl  
   
 sqlite: (not affected by security vulnerabilities so far)  
 amarok  
 monotone  
 iceweasel  
   
 util-linux/mount:  
 loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb  
   
 webmin:  
 usermin (only in sarge)  
   
 sylpheed:  
 sylpheed-claws  
   
 phpsysinfo:  
 egroupware  
 phpgroupware  
   
 phpldapadmin:  
 egroupware (removed from egroupware after sarge)  
   
 chmlib:  
 kchmviewer (ships the code but links dynamically)  
   
 libavcodec/libavformat (source: ffmpeg):  
 mplayer (#395252)  
 xvidcap  
 kino (links statically, does not include code)  
 vlc (links statically, does not include code)  
 smilutils (links statically, does not include code)  
 motion (links statically, does not include code)  
 gst-ffmpeg  
 gstreamer0.10-ffmpeg  
 xmovie  
283    
284  mad MPEG decoding lib:  libmpeg2
285  mad          - mpeg2dec <unfixed> (embed)
286  xine-lib          - xine-lib <unfixed> (embed)
287    
288  libdts:  libntlm
289  libdts          - wget <unfixed> (fork; bug #550436)
290  xine-lib          - curl <unfixed> (fork; bug #550437)
291            - cntlm <unfixed> (fork; bug #550438)
292    
293  flac:  uw-imap
294  flac          - pine <unfixed> (embed)
295  xine-lib          - alpine <unfixed> (embed)
296    
297  liba52:  imagemagick
298  a52dec          - graphicsmagick <unfixed> (fork)
 xine-lib  
299    
300  libmpeg2:  python-urlgrabber
301  mpeg2dec          - mercurial <unfixed> (embed; bug #531062)
 xine-lib  
302    
303  curl:  beautifulsoup
304  wget (code for NTLM authentication)          - python-mechanize <unfixed> (embed)
305    
306  TODO evaluate:  halibut
307  gimp-gap (potentially using ffmpeg code as well)          - nsis <unfixed> (fork)
308    
309  uw-imap:  libghttp
310  pine          - hotway <unfixed> (embed)
 alpine  
311    
312  imagemagick:  libsndfile
313  graphicsmagick          - ardour 1:2.7.1-1 (embed)
314    
315  halibut:  glibmm2.4
316  nsis          - ardour 1:2.7.1-1 (embed)
317    
318  libghttp:  libgnomecanvasmm2.6
319  hotway          - ardour 1:2.7.1-1 (embed)
320    
321  libsndfile:  libsigc++-2.0
322  ardour          - ardour 1:2.7.1-1 (embed)
323    
324  glibmm2.4:  soundtouch
325  ardour          - ardour 1:2.7.1-1 (embed)
326    
327  libgnomecanvasmm2.6:  libmms
328  ardour          - xine-lib <unfixed> (embed)
329            - mimms <unfixed> (embed)
330    
331  libsigc++-2.0:  fckeditor
332  ardour          - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
333            - moin 1.8.2-2 (embed; bug #452599)
334            - karrigell <removed> (embed; bug #452598)
335            - gforge 4.6.99+svn6225-1 (embed)
336            - request-tracker3.8 <unfixed> (embed)
337    
338  soundtouch:  ipatlas (not packaged in Debian)
339  ardour          - moodle <unfixed> (embed; bug #507185)
340    
341  libmms:  libphp-phpmailer
342  xine-lib          - moodle <unfixed> (embed; bug #507185)
343  mimms          - mahara <unfixed> (embed)
344            - symfony <unfixed> (embed)
345            [etch] - phpgroupware <unfixed> (embed)
346            NOTE: phpgroupware-felamimail is only in etch
347            - egroupware <unfixed> (embed; bug #504283)
348            - glpi <unfixed>
349    
350  FCKeditor: (packaged as fckeditor)  htmlArea (not packaged in Debian)
351  knowledgeroot          - moodle <unfixed> (embed)
 moin (452599)  
 karrigell (452598)  
 gforge-plugins-extra (fixed since 4.6.99+svn6225-1)  
352    
353    giflib
354            - wine <unfixed> (embed; bug #466181)
355    
356    bennu (not packaged in Debian, http://bennu.sourceforge.net)
357            - moodle <unfixed> (embed)
358    
359    smarty
360            - moodle 1.8.2-2 (embed; bug #471158)
361            - gallery2 2.2.5-2 (embed; bug #471160)
362            - mahara 0.9.2-2 (embed; bug #471201)
363            - gosa 2.4beta1-1 (embed; bug #471200)
364    
 Moodle contains lots of things:  
 AdoDB  
 AdoDB-XML Schema  
 ipatlas  
 PHPMailer  
 Smarty  
 htmlArea  
365  TinyMCE  TinyMCE
366  bennu          - wordpress 2.5.1-3 (embed; bug #478257)
367            - moodle <unfixed> (embed; bug #507185)
368            - knowledgeroot <unfixed> (embed)
369            - joomla <itp> (bug #326398)
370    
371    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
372            - scite <unfixed> (embed)
373            - qscintilla <unfixed> (embed)
374            - qscintilla2 <unfixed> (embed)
375            - geany <unfixed> (fork)
376            - anjuta <unfixed> (embed)
377    
378    libphp-adodb
379            - moodle <unfixed> (embed; bug #507185)
380            NOTE: also AdoDB-XML Schema
381            - gallery2 <unfixed> (embed)
382            - phppgadmin <unfixed> (embed)
383            - egroupware <unfixed> (embed)
384            - phpwiki <unfixed> (embed)
385            - torrentflux 2.0beta1-2 (embed)
386            - ipplan <unfixed> (embed)
387            - typo3-src <unfixed> (embed)
388            - cacti <unknown> (embed)
389            [sarge] - cacti <unfixed> (embed)
390            NOTE: dependency exists, but internal version is used
391            - gforge 4.7~rc2-6 (embed)
392            - mahara <unfixed> (embed)
393    
394    gzip
395            - linux-kernel <unfixed> (embed)
396            NOTE: lib/inflate.c
397            - klibc <unfixed> (embed)
398            NOTE: based on linux-kernel gzip code
399            - busybox <unfixed> (embed)
400    
401    neon
402            - cadaver 0.22.3+debian-1 (embed; bug #188381)
403            - gnome-vfs2 <unfixed> (embed; bug #395874)
404            [etch] - litmus <unfixed> (embed; #395875)
405            - litmus <removed> (embed; #395875)
406            [sarge] - screem <unfixed> (embed)
407            - sitecopy 1:0.16.3-5 (embed; bug #395876)
408            [etch] - tla <unfixed> (embed; bug #395877)
409            [sarge] - tla <unfixed> (embed; bug #395877)
410    
411    libmodplug
412            - gst-plugins-bad0.10 <unfixed> (embed)
413    
414    libvncserver
415            - vino <unfixed> (embed)
416    
417    putty
418            - filezilla <unfixed> (embed)
419    
420    tinyxml (not packaged in Debian)
421            - filezilla <unfixed>
422    
423    gv
424            - evince <unfixed> (embed)
425            NOTE: ps/ tree from gv 3.5.8
426            NOTE: evince-gtk is affected (a component of evince source package)
427    
428    libXbae
429            - paw <removed> (embed)
430            [etch] - paw <unfixed> (embed)
431    
432    libgtkhtml
433            - claws-mail-extra-plugins <unfixed> (fork)
434    
435    libXaw
436            - paw <removed> (embed)
437            [etch] - paw <unfixed> (embed)
438            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
439    
440    libgd2
441            - graphviz <unfixed> (embed)
442            NOTE: lib/gd seems to be 2.0.33
443            - wml <unfixed> (embed)
444            - libwmf <unfixed> (embed)
445            NOTE: derived from gd 1.6.3
446    
447    rar
448            - unrar-nonfree <unfixed> (embed)
449    
450    unrar-free (maybe this code is derived from the original rar, too?)
451            - clamav <unfixed> (embed)
452            NOTE: seems to be disabled in default config
453    
454    mplayer (DirectMedia Object loader)
455            - xine-lib <unfixed> (embed)
456            NOTE: src/libw32dll/
457            - vlc <unfixed> (embed)
458            NOTE: modules/codec/dmo/
459            - mplayer 1.0~rc2-20 (embed)
460    
461    libwpd (WordPerfect converter)
462            - openoffice.org <unfixed> (embed)
463    
464    fsplib (http://sourceforge.net/projects/fsp/)
465            - gftp <unfixed> (embed)
466            NOTE: lib/fsplib version 0.3
467    
468    sprng
469            - tree-puzzle <unfixed> (embed)
470    
471    librpcsecgss
472            - krb5 <unfixed> (embed)
473    
474    jasper
475            - ghostscript <unfixed> (embed)
476            - gs-gpl <unfixed> (embed)
477    
478    libiris
479            - psi <unfixed> (embed)
480            - kdenetwork <unfixed> (embed)
481            NOTE: kopete embeds libiris but links dynamically to libidn
482            - kdegames <unfixed> (embed)
483            NOTE: ksirk/kde4
484    
485    libidn
486            - monotone 0.43-1 (embed)
487            - psi <unfixed> (embed)
488            NOTE: psi embeds libiris which embeds libidn
489            - kdegames <unfixed> (embed)
490            NOTE: kdegames/kde4 embeds libiris which embeds libidn
491    
492    liblua
493            - monotone 0.43-1 (embed)
494            - nmap 5.00-1 (embed; bug #527997)
495            [lenny] - nmap <unfixed> (embed; bug #527997)
496    
497    libbotan
498            - monotone 0.43-1 (embed)
499    
500    NetXX
501            - monotone 0.43-1 (embed)
502    
503    libgc
504            - mono <unfixed> (embed)
505    
506    lzma
507            - p7zip <unfixed> (embed)
508            - xz-utils <unfixed> (fork)
509    
510    lzo
511            - grub2 <unfixed> (embed)
512    
513    yassl
514            - mysql-dfsg-5.0 <unfixed> (embed)
515    
516    pax code
517            - tar <unfixed> (embed)
518            - cpio <unfixed> (embed)
519    
520    t1lib
521            - tetex-bin 2.0.2-1 (embed)
522            - texlive-bin <unknown> (embed)
523    
524    guichan
525            - boswars <unfixed> (embed)
526            NOTE: maintainer notified us, working on it
527    
528    tolua
529            - boswars <unfixed> (embed)
530            NOTE: maintainer notified us, working on it
531    
532    asio-dev
533            - luxrender <removed> (embed)
534    
535    xine-lib
536            - vlc <unfixed> (embed)
537            NOTE: only parts included in modules/access/rtsp
538    
539    netpbm
540            - tcl8.3 <unfixed> (embed)
541            - tcl8.4 <unfixed> (embed)
542            - tcl8.5 <unfixed> (embed)
543            NOTE: generic/tkImgGIF.c
544    
545    tk8.5
546            - tk8.0 <removed> (old-version)
547            - tk8.3 <unfixed> (old-version)
548            - tk8.4 <unfixed> (old-version)
549            - perl-tk <unfixable> (fork)
550    
551    samba
552            - mc 2:4.6.2~git20080311-1 (embed)
553            NOTE: maintainer is aware of this, currently searching a solution
554    
555    plib1.8.4c2
556            - boson <unfixed> (fork)
557            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
558    
559    fribidi
560            - quesoglc <unfixed> (embed)
561            NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
562    
563    glew
564            - quesoglc <unfixed> (embed; bug #489341)
565            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
566    
567    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
568            - transcend <unfixed> (embed)
569            - cultivation <unfixed> (embed)
570            - passage <unfixed> (embed)
571            - gravitation <unfixed> (embed)
572    
573    tar
574            - libarchive <unfixed> (embed)
575            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
576    
577    cpio
578            - libarchive <unfixed> (embed)
579            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
580    
581    webkit
582            - qt4-x11 <unfixed> (embed)
583    
584    ftgl
585            - blender 2.46+dfsg-1 (embed)
586    
587    wv
588            - abiword <unfixed>
589    
590    qemu
591            - kvm <unfixed> (embed; bug #543159)
592            - xen-3 <unfixed> (embed)
593            - xen-unstable <unfixed> (embed)
594    
595    vgabios
596            - kvm <unfixed> (embed; bug #489442)
597    
598    bochs
599            - kvm <unfixed> (embed; bug #489442)
600    
601    speex
602            - vorbis-tools <unfixed> (embed)
603            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
604            - gst-plugins-good0.10 <unfixed> (embed)
605            - xine-lib <unfixed> (embed)
606            - libfishsound <unfixed> (embed)
607            - libannodex <unfixed> (embed)
608            - vlc <unfixed> (embed)
609            - xmms-speex <unfixed> (embed)
610            - libsdl-sound1.2 <unfixed> (embed)
611            - sweep <unfixed> (embed)
612    
613    libreadline
614            - magic <itp> (old-version)
615    
616    opcode
617            - ode <unfixed> (embed)
618            NOTE: opcode is not a package in debian, it is just embedded
619            NOTE: http://www.codercorner.com/Opcode.htm
620    
621    gimpact
622            - ode <unfixed> (embed)
623            NOTE: gimpact is not a package in debian, it is just embedded
624            NOTE: http://gimpact.sf.net
625    
626    mochikit
627            - mahara <unfixed> (embed)
628            NOTE: they require extra patches, still unmerged upstream
629            - ntop <unfixed> (embed)
630            - coherence <unfixed> (embed)
631            NOTE: python-coherence
632            - paste <unfixed> (embed)
633            NOTE: python-paste
634            - turbogears <unfixed> (embed)
635            NOTE: python-turbogears
636            - plone3 <unfixed> (embed)
637            NOTE: zope-plone3
638    
639    prototypejs
640            - netbeans-ide 6.0.1+dfsg-2 (embed)
641            - auth2db <unfixed> (embed)
642            - webcit <unfixed> (embed)
643            NOTE: citadel-webcit
644            - asterisk <unfixed> (embed)
645            - doc-iana <unfixed> (embed)
646            - libaws <unfixed> (embed)
647            NOTE: libaws-doc
648            - libgettext-ruby <unfixed> (embed)
649            NOTE: libgettext-ruby-data
650            - libjson-ruby <unfixed> (embed)
651            NOTE: libjson-ruby-doc
652            - lucene2 <unfixed> (embed)
653            NOTE: liblucene2-java-doc
654            - libopenid-ruby <unfixed> (embed)
655            - solr <unfixed> (embed)
656            NOTE: solr-common
657            - glpi <unfixed> (embed)
658            - mnemo2 <unfixed> (embed)
659            - nag2 <unfixed> (embed)
660            - knowledgeroot <unfixed> (embed)
661            - mediatomb <unfixed> (embed)
662            NOTE: mediatomb-common
663            - mt-daapd <unfixed> (embed)
664            - op-panel <unfixed> (embed)
665            - ebug-http <unfixed> (embed)
666            - phpgedview <removed> (embed)
667            - poker-network <unfixed> (embed)
668            NOTE: poker-web
669            - webhelpers <unfixed> (embed)
670            NOTE: python-webhelpers
671            - qwik <unfixed> (embed)
672            - rails <unfixed> (embed)
673            - typo3-src <unfixed> (embed)
674            - wordpress 2.5.0-2 (embed)
675            - zope <unfixed> (embed)
676            NOTE: zope-plone3
677            - smokeping <unfixed> (embed)
678            - ampache 3.4.1-2 (embed)
679            - exaile <unfixed> (embed)
680            - hobix <unfixed> (embed)
681            - pixelpost <unfixed> (embed)
682            - symfony <unfixed> (embed)
683            NOTE: it's been said that there are custom changes
684            - zabbix <unfixed> (embed)
685            NOTE: zabbix-frontend-php
686            - turba2 <unfixed> (embed)
687    
688    gdb
689            - insight <unfixed> (embed)
690    
691    e2fsprogs
692            - ldiskfsprogs <unfixable> (fork)
693    
694    quazip (not packaged in Debian)
695            - qcake <unfixed> (embed)
696            NOTE: starting with upstream version 0.6.4
697    
698    exo
699            - pcmanfm <unfixed> (embed; bug #499677)
700            NOTE: slightly modified source code
701    
702    java
703            - openjdk-6 <unfixed>
704            - sun-java5 <unfixed>
705            - sun-java6 <unfixed>
706    
707    libphp-snoopy
708            - ampache 3.4.1-2 (embed; bug #504169)
709            - mahara 1.0.5-2 (embed; bug #504170)
710            - pixelpost 1.7.1-5 (embed; bug #504171)
711            - mediamate 0.9.3.6-5 (embed; bug #504172)
712            - opendb <removed> (embed; bug #504173)
713            [etch] - opendb <unfixed> (embed; bug #504173)
714            - wordpress 2.5.1-9 (embed; bug #443948)
715            - moodle <unfixed> (embed; bug #507185)
716            [etch] - phpgroupware <unfixed> (embed)
717            NOTE: phpgroupware-felamimail
718            - magpierss 0.72-3 (embed; bug #431089)
719    
720    jquery
721            - zekr <unfixed> (embed)
722            - wordpress <unknown> (embed)
723            - yocto-reader <unfixed> (embed)
724            - textpattern <unfixed> (embed)
725            - genshi 0.5.1-1 (embed)
726            NOTE: compressed file under examples/ dir
727            - prewikka <unfixed> (embed)
728            - libramaze-ruby <unfixed> (embed)
729            - drupal5 <unfixed> (embed)
730            - b2evolution <unfixed> (embed)
731            - wesnoth <unfixed> (embed)
732    
733    tablesorter (jquery plugin, not packaged yet)
734            - wesnoth <unfixed> (embed)
735    
736    kses
737            - wordpress <unfixed> (embed; bug #504242)
738            NOTE: their copy has all methods renamed to wp_<foo>
739            NOTE: kses isn't in Debian, RFP: #504240
740            - moodle <unfixed> (embed; bug #507185)
741            - egroupware <unfixed> (embed)
742    
743    magpierss
744            - wordpress <unfixed> (embed; bug #504242)
745            - moodle <unfixed>
746    
747    php-gettext
748            - wordpress 2.8.4-1 (embed; bug #504242)
749    
750    libphp-ixr (name may change, it is the Incutio XML-RPC)
751            - wordpress <unfixed> (embed; bug #504242)
752            NOTE: libphp-ixr isn't in Debian, RFP: #504236
753            - dokuwiki <unfixed> (embed)
754            - textpattern <unfixed> (embed)
755    
756    libphp-cas
757            - glpi <unfixed> (embed)
758            - moodle <unfixed> (embed; bug #505984)
759    
760    scriptaculous
761            - glpi <unfixed> (embed)
762            - libaws <unfixed> (embed)
763            NOTE: libaws-doc
764            - op-panel <unfixed> (embed)
765            - symfony <unfixed> (embed)
766            NOTE: maintainer says there are extra incompatible changes required
767            - pixelpost <unfixed> (embed)
768            - webhelpers <unfixed> (embed)
769            NOTE: python-webhelpers
770            - qwik <unfixed> (embed)
771            - smokeping <unfixed> (embed)
772            - turba2 <unfixed> (embed)
773            - typo3-src 4.2.3-1 (embed)
774    
775    libmarkdown-php
776            - moodle <unfixed> (embed; bug #507185)
777            - pixelpost <unfixed> (embed)
778    
779    php-openid
780            - wordpress-openid <itp> (embed)
781    
782    geshi
783            - dokuwiki 0.0.20080505-3.1 (embed)
784            - pgfouine 1.0-1.1 (embed)
785            - websvn 2.1.0-1 (embed)
786    
787    webcalendar
788            - gforge 4.7~rc2-6 (embed; bug #504758)
789    
790    libical
791            - kdepim <unfixed> (fork)
792            - kdepimlibs <unfixed> (fork)
793            NOTE: fixed in KDE4 post 4.1.x series
794            - claws-mail-extra-plugins <unfixed> (fork)
795    
796    libltdl3
797            - kdelibs <unfixed> (embed)
798            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
799            - synfig <unfixed> (embed)
800    
801    harfbuzz
802            - qt4-x11 <unfixed> (embed)
803    
804    libzip
805            - php5 <unfixed> (fork)
806            - odt2txt <unfixed> (embed; bug #523808)
807    
808    json.php (not packaged; should be replaced with php's built-in functions)
809            - moodle <unfixed>
810            - yui <unfixed>
811            - gallery2 <unfixed>
812            - dokuwiki <unfixed>
813            - typo3-src <unfixed>
814    
815    php-fpdf
816            - tcpdf <itp> (fork)
817            - moodle <unfixed>
818            - phpwiki <unfixed>
819            - egroupware <unfixed>
820            - ldap-account-manager <unfixed> (fork)
821    
822    tcpdf (itp: #495985)
823            - moodle <unfixed>
824            - phpmyadmin <unfixed>
825    
 TinyMCE:  
 wordpress  
 moodle  
 knowledgeroot  
 joomla (ITP)  
   
 scintilla:  
 scite  
 qscintilla  
 qscintilla2  
 geany  
   
 libphp-adodb:  
 gallery2  
 phppgadmin  
 egroupware  
 phpwiki  
 ipplan  
826  typo3  typo3
827  moodle          - moodle <unfixed>
 cacti (dependency exists, but internal version is used -- only in sarge, fixed in etch)  
828    
829  gzip:  spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
830  linux-kernel (lib/inflate.c)          - moodle <unfixed>
831  klibc (based on linux-kernel gzip code)          - gosa <unfixed>
 busybox  
832    
833  neon:  php-ole (itp: #487558)
834  cadaver (all, but being worked on: #188381)          - moodle <unfixed>
 gnome-vfs2 (#395874)  
 litmus (#395875)  
 screem (sarge only)  
 sitecopy (#395876)  
 tla (etch/sid only: #395877)  
835    
836  libmodplug:  pieforms (http://www.catalyst.net.nz)
837  gst-plugins-bad0.10          - mahara <unfixed>
838    
839  libvncserver:  savant2 (http://phpsavant.com)
840  vino          - egroupware <unfixed>
841    
842  putty:  rssparser (http://nwow.org)
843  filezilla          - egroupware <unfixed>
844            - phpgroupware <unfixed>
845    
846  tinyxml (not packaged in Debian):  lcms
847  filezilla          - openjdk-6 <unfixed> (fork)
848    
849  gv:  libphp-phplayersmenu
850  evince (ps/ tree from gv 3.5.8)          - diogenes <unfixed>
851  evince-gtk (not packaged in Debian)          - phpldapadmin <unfixed>
852    
853  libXbae:  libphp-pclzip
854  libpawlib2-lesstif package (from Cernlib)          - docvert <unfixed>
855            - moodle <unfixed>
856            - egroupware <unfixed>
857    
858  libXaw:  libphp-simplepie
859  libpawlib2-lesstif package (from Cernlib)          - dokuwiki <unfixed>
860    
861  (I plan to deal with the above two cases after Etch release. -- KevinMcCarty)  libphp-jpgraph
862            - egroupware <unfixed>
863    
864  libgd2:  php-simpletest
865  graphviz (lib/gd seems to be 2.0.33)          - moodle <unfixed>
866    
867  rar:  libpng
868  unrar-nonfree          - iceweasel <not-affected> (uses xulrunner)
869            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
870            - iceape 1.0.13~pre080614i-0etch1 (embed)
871            - xulrunner 1.9.0.13-1 (embed)
872            [lenny] - xulrunner 1.9.0.11-0lenny1
873            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
874            - gamera 3.2.3-1 (embed)
875    
876  unrar-free: (maybe this code is derived from the original rar, too?)  irssi
877  clamav (seems to be disabled in default config)          - silc-client <unfixed> (embed)
878            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
879    
880  mplayer (DirectMedia Object loader):  extc
881  xine-lib (src/libw32dll/)          - mtasc <unfixed> (embed)
882  vlc (modules/codec/dmo/)          - haxe <unfixed> (embed)
883    
884  libwpd (WordPerfect converter):  swflib
885  openoffice.org          - mtasc <unfixed> (embed)
886            - haxe <unfixed> (embed)
887    
888  fsplib (http://sourceforge.net/projects/fsp/):  libitext-java
889  gftp (lib/fsplib version 0.3)          - bouncycastle 2.1.4-1 (embed)
890    
891  librpcsecgss:  python-ply
892  krb5          - pyke <unfixed> (embed)
893    
894  jasper:  libdumbnet (libdnet upstream)
895  ghostscript          - nmap <unfixed> (fork)
 gs-gpl  
896    
897  libidn:  gcc-4.4
898  monotone          - gcc-mingw32 <unfixed> (embed)
899    
900  liblua:  camlimages
901  monotone          - advi <unfixed> (static; bug #550441)
902    
903  libbotan:  memcached
904  montone          - memcachedb <unfixed> (embed)
905    
906  NetXX:  yajl
907  monotone          - argyll <unfixed> (embed; bug #544223)
908            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
909    
910  libgc:  libept
911  mono          - adept <unfixed> (embed; bug #540649)
912    
913  lzma:  libvorbis
914  p7zip          - iceweasel <not-affected> (uses xulrunner)
915            - xulrunner <not-affected> (introduced in 1.9.1)
916            TODO: recheck when xulrunner 1.9.1 enters unstable [- xulrunner <unfixed> (embed; bug #540959)]
917    
918  lzo:  cairo
919  grub2          - iceweasel <not-affected> (uses xulrunner)
920            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
921    
922  pax code:  php-net-dnsbl
923  tar          - serendipity <unfixed> (embed)
924  cpio  
925    php-onyx-rss
926            - serendipity <unfixed> (embed)
927    
928    php-text-wiki
929            - serendipity <unfixed> (embed)
930    
931    php-xml-rpc
932            - serendipity <unfixed> (embed)
933    
934    polarssl (does not have a shared library)
935            - pdkim <itp> (embed; bug #543150)
936            - xyssl <unfixed> (old-version)
937    
938    pidgin
939            - gaim <removed> (old-version)
940    
941    icu
942            - webkit 1.0.1-1 (embed; bug #547214)
943            - texlive-bin <unfixed> (fork)
944            NOTE: texlive upstream working with icu upstream to merge their changes
945    
946    cyrus-imapd-2.2
947            - kolab-cyrus-imapd <unfixed> (fork)
948            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
949    
950    python-cxx-dev
951            - freecad <unfixed> (embed; bug #547936)
952    
953    libzipios++-dev
954            - freecad <unfixed> (embed; bug #547941)
955    
956    linux-2.6
957            - kvm <unfixed> (embed; bug #549973) [./kernel/*]
958            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
959            - kernel-source-2.6.8 <removed> (old-version)
960            - kernel-source-2.4.27 <removed> (old-version)
961            - kernel-source-2.4.24 <removed> (old-version)
962            - kernel-source-2.2.25 <removed> (old-version)
963            - kernel-source-2.2.20 <removed> (old-version)
964    
965    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
966            - kvm <unfixed> (embed) [./libfdt/*]
967    
968    qweb (not packaged)
969            - ajaxterm <unfixed>
970    
971    opensaml2
972            - opensaml <removed> (old-version)
973    
974    shibboleth-sp2
975            - shibboleth-sp <removed> (old-version)
976    
977    tuxonice-userui
978            - suspend2-userui <removed> (old-version)
979    
980    expat
981            - w3c-libwww <removed> (embed; bug #551941)
982            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
983            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
984    
985    xerces-c
986            - xerces-c2 <unfixed> (old-version)
987            - xerces27 <removed> (old-version)
988    
989    md5 (RSA's version; not the gnu version provided by coreutils)
990            - w3c-libwww <removed> (embed; bug #551942)
991            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
992    
993    enet
994            - sauerbraten <unfixed> (embed; #497194)
995    
996    eglibc
997            - glibc <removed> (old-version)
998    
999  t1lib:  galib
1000  tetex-bin (links to system t1lib since 2.0.2)          - gamera 3.2.3-1 (embed)
 texlive-bin (links to system t1lib)  
1001    
1002    configobj
1003            - bzr <unfixed> (embed)
1004            - elisa <unfixed> (embed)
1005            - gaupol <unfixed> (embed)
1006            - ipython <unfixed> (embed)
1007            - pida <unfixed> (embed)
1008            - psychopy <unfixed> (embed)
1009            - rest2web <unfixed> (embed)
1010            - auth2db <unknown> (embed)
1011            - dynagen <unknown> (embed)
1012            - iceweasel <unknown> (embed)
1013            - sabnzbdplus <unknown> (embed)
1014            - xulrunner <unknown> (embed)
1015            - nipy <not-affected> (embed) [./examples/neurospin/neurospy/configobj.py]

Legend:
Removed from v.7700  
changed lines
  Added in v.13146

  ViewVC Help
Powered by ViewVC 1.1.5