/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Contents of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log


Revision 13559 - (show annotations) (download)
Tue Dec 15 20:23:03 2009 UTC (3 years, 5 months ago) by jmm-guest
File size: 45302 byte(s)
another update on ltdl
1 Embedded code copies
2 ====================
3
4 This file collects source packages that embed code from other projects.
5 This is considered bad for fixing security flaws because the fix needs
6 to be applied in multiple source packages.
7
8 Format:
9 <srcpkg> (<optional comment about srcpkg>)
10 - <embedding srcpkg> <status> (<sort>; bug #<number>)
11 NOTE: optional comments about the linkage of the embedding srcpkg
12
13 status: version number fixing the embedded copy, <unfixed>, <removed>,
14 <itp>, <not-affected>, <unknown> if the version number can not
15 be determined, or <unfixable> for unavoidable cases (e.g., forks
16 that add real value)
17 sort: static (linking statically against a lib)
18 embed (embedding a copy of the library into another source package)
19 fork (the package is not just embedding code but it is a fork and
20 thus might share parts of the source code)
21 old-version (the package is an older version of essentially
22 the same code)
23
24 The srcpkg might be some string to identify the code if there is no
25 specific source package.
26
27 Everything up to the next line is ignored.
28 ---BEGIN
29 xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
30 NOTE: Fixed packages link to poppler library unless otherwise noted
31 - pdftohtml <unknown>
32 [sarge] - pdftohtml <unfixed>
33 [etch] - pdftohtml <unfixed>
34 NOTE: has been replaced by poppler-utils
35 - kdegraphics 4:4.2.2-1 (embed; bug #436164)
36 - texlive-base 3.0-12 (embed)
37 - texlive-bin 2007-1 (embed)
38 NOTE: links to poppler
39 - koffice <unfixed> (embed; bug #436163)
40 - libextractor 0.5.12-1 (embed)
41 NOTE: libextractor is using its own pdf decoder now
42 - ipe <unfixed> (embed)
43 NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44 - ruby-gnome2 <unknown> (embed)
45 NOTE: copy only present in source but links to poppler
46 - pdfedit <unfixed> (embed; bug #510794)
47 - swftools <unfixed> (embed; bug #551293)
48 - poppler <unfixable> (fork)
49
50 ppmd
51 - libcomplearn-mod-ppmd <unfixed> (fork)
52 NOTE: discussion in #458152
53
54 libevent
55 - transmission 1.71-1 (embed; bug #529372)
56
57 lrmi
58 - read-edid 2.0.0-1 (embed; bug #495131)
59 - s3switch <unfixed> (embed)
60 - xresprobe <unfixed> (embed)
61 - zhcon <unfixed> (embed)
62
63 peercast
64 - gnome-peercast <removed> (embed)
65 [etch] - gnome-peercast <unfixed> (embed)
66
67 silc-toolkit
68 - silc-client 1.1~beta6-1 (embed)
69
70 icclib
71 - ghostscript <unfixed> (embed)
72 - argyll <unfixed> (embed)
73
74 dietlibc
75 - ccontrol 0.9.1+20071204-1 (static)
76
77 libmikmod
78 - sdl-mixer1.2 <unfixed> (embed)
79 TODO: report bug
80
81 libiax
82 - iaxmodem <unfixable> (embed; bug #548885)
83
84 spandsp
85 - iaxmodem <unfixable> (embed; bug #548885)
86
87 zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
88 - dpkg <unfixed> (static)
89 NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
90 - rsync <unfixed> (embed)
91 NOTE: somehow derived code base
92 - mono <unfixed> (embed)
93 TODO: check mozilla
94 - Linux kernels <unfixed> (embed)
95 - pvpgn 1.7.8-2 (embed)
96 - mrtg 2.12.2-1 (embed)
97 - rpm <unknown> (embed)
98 NOTE: pinged anibal since when rpm was fixed
99 - tuxcmd-modules <unfixed> (embed)
100 - zsync <unfixed>
101 - tra <unfixed>
102 - sash <unfixed>
103 - nsis <unfixed>
104 - mseide-msegui <unfixed>
105 NOTE: mseide
106 - mirrordir <unfixed>
107 - poco <unfixed>
108 - klibc <unfixed>
109 - ghostscript <unfixed>
110 - freeimage <unfixed>
111 - clamav <unfixed> (fork)
112 NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
113 - tuxonice-userui <unfixed>
114 - plt-scheme <unfixed>
115 - perl <unfixed>
116 - paraview <unfixed>
117 - gcvs <unfixed>
118 - dump <unfixed>
119 - aide <unfixed> (static)
120 - dar <unfixed> (static)
121 - avfs <unfixed>
122 - fpc <unfixed>
123 - winff <unfixed>
124 NOTE: inherited from fpc, see #472304
125 - lazarus <unfixed>
126 NOTE: inherited from fpc, see #472304
127 - erlang <unfixed> (embed)
128 - gamera 3.2.3-1 (embed)
129 - python2.4 <unfixed> (embed; bug #553403)
130 - python2.5 <unfixed> (embed; bug #553403)
131
132 dulwich
133 - hg-git 0.1.0-1 (embed; bug #541996)
134
135 libvigraimpex
136 - hugin <unfixed> (embed; bug #542259)
137 - enblend-enfuse <unfixed> (embed; bug #542258)
138 - gamera 3.2.3-1 (embed)
139
140 libbz2
141 - dpkg <unfixed> (static)
142
143 libgadu
144 - centerim <unfixed> (embed; bug #559783)
145 - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
146 - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
147 - kdenetwork 4:3.3.2-5 (embed)
148 NOTE: from kdenetwork: kopete
149 - ekg 1:1.8~rc0-1 (embed)
150 - kadu 0.6.0.2-3 (embed; bug #504430)
151 - gadu <itp> (embed)
152
153 xmlrpc (which package is the "origin" of this code?)
154 - drupal <unfixed> (embed)
155 - phpgroupware <unfixed> (embed)
156 - egroupware <unfixed> (embed)
157 - phpwiki <unfixed> (embed)
158 - php4 <unfixed> (embed)
159 TODO: check, php-pear, IIRC this was reorganized some weeks ago?
160
161 shtool (affects build-time only)
162 - mysql-ocaml <unfixed> (embed)
163 - php4 <unfixed> (embed)
164
165 iceape
166 - iceweasel <unfixed> (fork)
167 - icedove <unfixed> (fork)
168 - xulrunner <unfixed> (fork)
169 - kompozer <unfixed> (embed; bug #532168)
170 - galeon <unfixed> (fork)
171 - epiphany-browser <unfixed> (fork)
172 - conkeror <unfixed> (fork)
173 - kazehakase <unfixed> (fork)
174
175 xli
176 - xloadimage <unfixed> (embed)
177
178 lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
179 - openmotif <unfixed> (embed)
180 - libxpm <unfixed> (embed)
181
182 kerberized apps with BSD origin
183 - krb4 <removed> (embed)
184 - krb5 <unfixed> (embed)
185 - heimdal <unfixed> (embed)
186
187 grip (which pkg is the origin?)
188 - libcdaudio <unfixed>
189 - grip <unfixed>
190 - gnome-vfs <unfixed>
191 TODO: check vfs2 as well
192
193 fudforum
194 [etch] - phpgroupware <unfixed> (embed)
195 NOTE: phpgroupware-fudforum
196 [sarge] - egroupware-fudforum <removed> (embed)
197
198 libbsd
199 - rdate 1:1.2-3 (embed)
200 - atheme-services <unfixed>
201 - libbsd-arc4random-perl <unfixed>
202 - isakmpd <unfixed>
203 - bsdgames <unfixed> (embed)
204 - bsd-mailx <unfixed> (embed)
205 - netcat-openbsd <unfixed> (embed; bug #550611)
206 - openssh <unfixed> (embed)
207 - unworkable <unfixed> (embed)
208
209 cvs
210 - gcvs <unfixed> (embed)
211 NOTE: see cvsunix/src in tarball
212
213 pcre3
214 - php4 <unknown> (embed)
215 - analog 2:5.23-0woody1 (embed)
216 - goffice <unfixed> (embed)
217 NOTE: libgoffice-*
218 - vfu 4.06-4.1 (embed; bug #450754)
219 - tf5 5.0beta7-1 (embed)
220 - monotone 0.43-1 (embed)
221 NOTE: this only affects versions >= 0.37
222 - glib2.0 2.15.2-1 (embed)
223 - apache2 2.0.53-4 (embed)
224 - exim4 4.10-0.srh20.12 (embed)
225 - yacas <unfixed> (embed)
226 NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
227 - gtamsanalyzer.app 0.42-5 (embed)
228 - tin 980117-1 (embed)
229 - kazehakase 0.5.2-1
230 - webkit 1.0.1-1 (embed)
231 - qt4-x11 <unfixed> (embed)
232 NOTE: embedded via webkit copy
233 - erlang <unfixed> (embed)
234
235 tiff
236 - wxwindows2.4 2.2.1 (embed)
237 - gamera 3.2.3-1 (embed)
238
239 uudeview
240 - libconvert-uulib-perl <unfixed> (embed)
241 - pan <unfixed> (embed)
242
243 sqlite (not affected by security vulnerabilities so far)
244 - amarok <unfixed> (embed)
245 - monotone 0.43-1 (embed)
246 - iceweasel <unfixed> (embed)
247 - heimdal <unfixed> (embed; bug #559616)
248
249 util-linux/mount
250 - loop-aes-utils <unfixed> (embed)
251 NOTE: contains code from util-linux' mount in the mount-aes-udeb
252
253 sylpheed
254 - sylpheed-claws <unfixed> (fork)
255
256 phpsysinfo
257 - egroupware <unfixed> (embed)
258 - phpgroupware <unfixed> (embed)
259
260 phpldapadmin
261 [sarge] - egroupware <unfixed> (embed)
262 NOTE: removed from egroupware after sarge
263
264 chmlib
265 - kchmviewer <unknown> (embed)
266
267 ffmpeg (libavcodec/libavformat)
268 - mplayer 1.0~rc2-14 (embed; bug #395252)
269 - kino 1.0.0-1
270 - vlc <not-affected> (Links dynamically since initial release)
271 - smilutils 0.3.0-10
272 NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
273 - motion 3.1.19-1
274 - gstreamer0.10-ffmpeg 0.10.3-2
275 - xmovie <removed> (static)
276 TODO: gimp-gap (potentially using ffmpeg code as well)
277 - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
278 - audacity 1.3.7-2 (embed; bug #512278)
279
280 faad2
281 - mplayer 1.0~rc2-20 (embed)
282 - avifile <unfixed> (embed; bug #538750)
283 - ffmpeg-debian <removed> (old-version)
284
285 libmad (MPEG decoding lib)
286 - xine-lib <unfixed> (embed)
287 - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
288 TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
289
290 libdts
291 - xine-lib <unfixed> (embed)
292
293 flac
294 - xine-lib <unfixed> (embed)
295
296 liba52
297 - a52dec <unfixed> (embed)
298 - xine-lib <unfixed> (embed)
299
300 libmpeg2
301 - mpeg2dec <unfixed> (embed)
302 - xine-lib <unfixed> (embed)
303
304 libntlm
305 - wget <unfixed> (fork; bug #550436)
306 - curl <unfixed> (fork; bug #550437)
307 - cntlm <unfixed> (fork; bug #550438)
308
309 uw-imap
310 - pine <unfixed> (embed)
311 - alpine <unfixed> (embed)
312
313 imagemagick
314 - graphicsmagick <unfixed> (fork)
315
316 python-urlgrabber
317 - mercurial <unfixed> (embed; bug #531062)
318 - w3af <unfixed> (embed; bug #555372)
319 [experimental] - harvestman <unfixed> (embed; bug #555373)
320
321 beautifulsoup
322 - python-mechanize <unfixed> (embed; bug #555349)
323 - zope2.11 <unfixed> (embed; bug #555350)
324 - twill <unknown> (embed)
325
326 halibut
327 - nsis <unfixed> (fork)
328
329 libghttp
330 - hotway <unfixed> (embed)
331
332 libsndfile
333 - ardour 1:2.7.1-1 (embed)
334
335 glibmm2.4
336 - ardour 1:2.7.1-1 (embed)
337
338 libgnomecanvasmm2.6
339 - ardour 1:2.7.1-1 (embed)
340
341 libsigc++-2.0
342 - ardour 1:2.7.1-1 (embed)
343
344 soundtouch
345 - ardour 1:2.7.1-1 (embed)
346
347 libmms
348 - xine-lib <unfixed> (embed)
349 - mimms <unfixed> (embed)
350
351 fckeditor
352 - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
353 - moin 1.8.2-2 (embed; bug #452599)
354 - karrigell <removed> (embed; bug #452598)
355 - gforge 4.6.99+svn6225-1 (embed)
356 - request-tracker3.8 <unfixed> (embed)
357
358 ipatlas (not packaged in Debian)
359 - moodle <unfixed> (embed; bug #507185)
360
361 libphp-phpmailer
362 - moodle <unfixed> (embed; bug #507185)
363 - mahara <unfixed> (embed)
364 - symfony <unfixed> (embed)
365 [etch] - phpgroupware <unfixed> (embed)
366 NOTE: phpgroupware-felamimail is only in etch
367 - egroupware <unfixed> (embed; bug #504283)
368 - glpi <unfixed>
369
370 htmlArea (not packaged in Debian)
371 - moodle <unfixed> (embed)
372
373 giflib
374 - wine <unfixed> (embed; bug #466181)
375
376 bennu (not packaged in Debian, http://bennu.sourceforge.net)
377 - moodle <unfixed> (embed)
378
379 smarty
380 - moodle 1.8.2-2 (embed; bug #471158)
381 - gallery2 2.2.5-2 (embed; bug #471160)
382 - mahara 0.9.2-2 (embed; bug #471201)
383 - gosa 2.4beta1-1 (embed; bug #471200)
384
385 TinyMCE
386 - wordpress 2.5.1-3 (embed; bug #478257)
387 - moodle <unfixed> (embed; bug #507185)
388 - knowledgeroot <unfixed> (embed)
389 - joomla <itp> (bug #326398)
390
391 scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
392 - scite <unfixed> (embed)
393 - qscintilla <unfixed> (embed)
394 - qscintilla2 <unfixed> (embed)
395 - geany <unfixed> (fork)
396 - anjuta <unfixed> (embed)
397
398 libphp-adodb
399 - moodle <unfixed> (embed; bug #507185)
400 NOTE: also AdoDB-XML Schema
401 - gallery2 <unfixed> (embed)
402 - phppgadmin <unfixed> (embed)
403 - egroupware <unfixed> (embed)
404 - phpwiki <unfixed> (embed)
405 - torrentflux 2.0beta1-2 (embed)
406 - ipplan <unfixed> (embed)
407 - typo3-src <unfixed> (embed)
408 - cacti <unknown> (embed)
409 [sarge] - cacti <unfixed> (embed)
410 NOTE: dependency exists, but internal version is used
411 - gforge 4.7~rc2-6 (embed)
412 - mahara <unfixed> (embed)
413
414 gzip
415 - linux-kernel <unfixed> (embed)
416 NOTE: lib/inflate.c
417 - klibc <unfixed> (embed)
418 NOTE: based on linux-kernel gzip code
419 - busybox <unfixed> (embed)
420
421 neon
422 - cadaver 0.22.3+debian-1 (embed; bug #188381)
423 - gnome-vfs2 <unfixed> (embed; bug #395874)
424 [etch] - litmus <unfixed> (embed; #395875)
425 - litmus <removed> (embed; #395875)
426 [sarge] - screem <unfixed> (embed)
427 - sitecopy 1:0.16.3-5 (embed; bug #395876)
428 [etch] - tla <unfixed> (embed; bug #395877)
429 [sarge] - tla <unfixed> (embed; bug #395877)
430
431 libmodplug
432 - gst-plugins-bad0.10 <unfixed> (embed)
433
434 libvncserver
435 - vino <unfixed> (embed)
436
437 putty
438 - filezilla <unfixed> (embed)
439
440 tinyxml (not packaged in Debian; itp bug #531968)
441 - filezilla <unfixed>
442 - crystalspace <unfixed> (embed)
443 - libwfut <unfixed> (embed)
444 - rarian <unfixed> (embed)
445 - bulletml <unfixed> (embed)
446 - pokerth <unfixed> (embed)
447 - qutecom <unfixed> (embed)
448 - sofa-framework <unfixed> (embed)
449 - yate <unfixed> (embed)
450 - antigrav <unfixed> (embed)
451 - balder2d <unfixed> (embed)
452 - cal3d <unfixed> (embed)
453 - criticalmass <unfixed> (embed)
454 - ember <unfixed> (embed)
455 - epiphany <unfixed> (embed)
456 - gambit <unfixed> (embed)
457 - noiz2sa <unfixed> (embed)
458 - ogre <unfixed> (embed)
459 - opencity <unfixed> (embed)
460 - openmovieeditor <unfixed> (embed)
461 - pouetchess <unfixed> (embed)
462 - tecnoballz <unfixed> (embed)
463 - trigger-rally <unfixed> (embed)
464 - xmoto <unfixed> (embed)
465 - mapnik <unknown> (embed)
466 NOTE: uses a different XML parser by default
467 - rrootage 0.23a-6 <embed>
468 NOTE: links to libbulltetml
469 - boson <unknown> (embed)
470 NOTE: the embedded code is unused
471
472 gv
473 - evince <unfixed> (embed)
474 NOTE: ps/ tree from gv 3.5.8
475 NOTE: evince-gtk is affected (a component of evince source package)
476
477 libXbae
478 - paw <removed> (embed)
479 [etch] - paw <unfixed> (embed)
480
481 libgtkhtml
482 - claws-mail-extra-plugins <unfixed> (fork)
483
484 libXaw
485 - paw <removed> (embed)
486 [etch] - paw <unfixed> (embed)
487 NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
488
489 libgd2
490 - graphviz <unfixed> (embed)
491 NOTE: lib/gd seems to be 2.0.33
492 - wml <unfixed> (embed)
493 - libwmf <unfixed> (embed)
494 NOTE: derived from gd 1.6.3
495
496 rar
497 - unrar-nonfree <unfixed> (embed)
498
499 unrar-free (maybe this code is derived from the original rar, too?)
500 - clamav <unfixed> (embed)
501 NOTE: seems to be disabled in default config
502
503 mplayer (DirectMedia Object loader)
504 - xine-lib <unfixed> (embed)
505 NOTE: src/libw32dll/
506 - vlc <unfixed> (embed)
507 NOTE: modules/codec/dmo/
508 - mplayer 1.0~rc2-20 (embed)
509
510 libwpd (WordPerfect converter)
511 - openoffice.org <unfixed> (embed)
512
513 fsplib (http://sourceforge.net/projects/fsp/)
514 - gftp <unfixed> (embed)
515 NOTE: lib/fsplib version 0.3
516
517 sprng
518 - tree-puzzle <unfixed> (embed)
519
520 librpcsecgss
521 - krb5 <unfixed> (embed)
522
523 jasper
524 - ghostscript 8.70~dfsg-2+b1 (embed)
525 - ghostscript <unfixed> (static)
526
527 libiris
528 - psi <unfixed> (embed)
529 - kdenetwork <unfixed> (embed)
530 NOTE: kopete embeds libiris but links dynamically to libidn
531 - kdegames <unfixed> (embed)
532 NOTE: ksirk/kde4
533
534 libidn
535 - monotone 0.43-1 (embed)
536 - psi <unfixed> (embed)
537 NOTE: psi embeds libiris which embeds libidn
538 - kdegames <unfixed> (embed)
539 NOTE: kdegames/kde4 embeds libiris which embeds libidn
540
541 liblua
542 - monotone 0.43-1 (embed)
543 - nmap 5.00-1 (embed; bug #527997)
544 [lenny] - nmap <unfixed> (embed; bug #527997)
545 - ocropus <unfixed> (embed)
546 - enigma <unfixed> (embed)
547 NOTE: requires lua built with C++
548 - freeciv <unfixed> (embed)
549
550 libbotan
551 - monotone 0.43-1 (embed)
552
553 NetXX
554 - monotone 0.43-1 (embed)
555
556 libgc
557 - mono <unfixed> (embed)
558
559 lzma
560 - p7zip <unfixed> (embed)
561 - xz-utils <unfixed> (fork)
562
563 lzo
564 - grub2 <unfixed> (embed)
565
566 yassl
567 - mysql-dfsg-5.0 <unfixed> (embed)
568
569 pax code
570 - tar <unfixed> (embed)
571 - cpio <unfixed> (embed)
572
573 t1lib
574 - tetex-bin 2.0.2-1 (embed)
575 - texlive-bin <unknown> (embed)
576
577 guichan
578 - boswars <unfixed> (embed)
579 NOTE: maintainer notified us, working on it
580
581 tolua
582 - boswars <unfixed> (embed)
583 NOTE: maintainer notified us, working on it
584 NOTE: actually tolua++
585 - ocropus <unfixed> (embed)
586 NOTE: actually tolua++
587 - freeciv <unfixed> (embed)
588 NOTE: actually tolua++
589 - enigma <unfixed> (embed)
590
591 asio-dev
592 - luxrender <removed> (embed)
593
594 xine-lib
595 - vlc <unfixed> (embed)
596 NOTE: only parts included in modules/access/rtsp
597
598 netpbm
599 - tcl8.3 <unfixed> (embed)
600 - tcl8.4 <unfixed> (embed)
601 - tcl8.5 <unfixed> (embed)
602 NOTE: generic/tkImgGIF.c
603
604 tk8.5
605 - tk8.0 <removed> (old-version)
606 - tk8.3 <unfixed> (old-version)
607 - tk8.4 <unfixed> (old-version)
608 - perl-tk <unfixable> (fork)
609
610 samba
611 - mc 2:4.6.2~git20080311-1 (embed)
612 NOTE: maintainer is aware of this, currently searching a solution
613
614 plib1.8.4c2
615 - boson <unfixed> (fork)
616 NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
617
618 fribidi
619 - quesoglc <unfixed> (embed)
620 NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
621
622 glew
623 - quesoglc <unfixed> (embed; bug #489341)
624 NOTE: waiting on GLEW_MX version of glew (see bug #474488)
625 - trigger <unfixed> (embed)
626 NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
627 - trigger-rally <unfixed> (embed)
628 NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
629
630 minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
631 - transcend <unfixed> (embed)
632 - cultivation <unfixed> (embed)
633 - passage <unfixed> (embed)
634 - gravitation <unfixed> (embed)
635
636 tar
637 - libarchive <unfixed> (embed)
638 NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
639
640 cpio
641 - libarchive <unfixed> (embed)
642 NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
643
644 webkit
645 - qt4-x11 <unfixed> (embed; bug #479851)
646 - kdelibs <unfixed> (old-version)
647 - kde4libs <unfixed> (fork)
648
649 ftgl
650 - blender 2.46+dfsg-1 (embed)
651
652 wv
653 - abiword <unfixed>
654
655 qemu
656 - kvm <unfixed> (embed; bug #543159)
657 NOTE: the kvm package will be removed from sid and squeeze soon (after
658 NOTE: which it will only be in experimental). superceded by qemu-kvm.
659 - qemu-kvm <unfixed> (embed; bug #560853)
660 - xen-3 3.4.2-2 (embed; bug #560856)
661 - xen-unstable <unfixed> (embed; bug #560856)
662
663 vgabios
664 - kvm <unfixed> (embed; bug #489442)
665
666 bochs
667 - kvm <unfixed> (embed; bug #489442)
668
669 speex
670 - vorbis-tools <unfixed> (embed)
671 NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
672 - gst-plugins-good0.10 <unfixed> (embed)
673 - xine-lib <unfixed> (embed)
674 - libfishsound <unfixed> (embed)
675 - libannodex <removed> (embed)
676 - vlc <unfixed> (embed)
677 - xmms-speex <unfixed> (embed)
678 - libsdl-sound1.2 <unfixed> (embed)
679 - sweep <unfixed> (embed)
680
681 libreadline
682 - magic <itp> (old-version)
683
684 opcode
685 - ode <unfixed> (embed)
686 NOTE: opcode is not a package in debian, it is just embedded
687 NOTE: http://www.codercorner.com/Opcode.htm
688
689 gimpact
690 - ode <unfixed> (embed)
691 NOTE: gimpact is not a package in debian, it is just embedded
692 NOTE: http://gimpact.sf.net
693
694 mochikit
695 - mahara <unfixed> (embed)
696 NOTE: they require extra patches, still unmerged upstream
697 - ntop <unfixed> (embed)
698 - coherence 0.6.2-1 (embed)
699 - paste <unfixed> (embed)
700 - turbogears <unfixed> (embed)
701 - plone3 <unfixed> (embed)
702 - xulrunner <unfixed> (embed)
703 - libjifty-plugin-chart-perl <unfixed> (embed)
704 - sabnzbdplus <unfixed> (embed)
705 - tgmochikit <unfixed> (embed)
706
707 prototypejs
708 - netbeans-ide 6.0.1+dfsg-2 (embed)
709 - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
710 - webcit <unfixed> (embed; bug #555219)
711 - asterisk 1:1.6.2.0~rc3-1 (embed)
712 - libjson-ruby 1.1.4-1 (embed; bug #555224)
713 - lucene2 2.9.1+ds1-2 (embed; bug #555226)
714 - horde3 <unfixed> (embed)
715 - knowledgeroot <unfixed> (embed; bug #555230)
716 - mediatomb <unfixed> (embed; bug #555233)
717 - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
718 - ebug-http <unfixed> (embed; bug #555236)
719 - phpgedview <removed> (embed)
720 - poker-network <unfixed> (embed; bug #555238)
721 - rails 2.1.0-6 (embed)
722 - wordpress 2.5.0-2 (embed; bug #555243)
723 - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
724 TODO: search through all of the other zope packages
725 - ampache 3.4.1-2 (embed)
726 - exaile 0.2.14+debian-2.1 (embed; bug #555245)
727 - hobix 0.5~svn20070319-4 (embed; bug #555247)
728 - zabbix 1.6.6-4 (embed; bug #555250)
729 - chora2 <unfixed> (embed; bug #555253)
730 - gollem <unfixed> (embed; bug # 555254)
731 - jscropperui 1.2.1-1 (embed; bug #555257)
732 - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
733 - ingo1 <unfixed> (embed; bug #555261)
734 - kronolith2 <unfixed> (embed; bug #555262)
735 - activeldap <unfixed> (embed)
736 - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
737 - mantis <unfixed> (embed; bug #555265)
738 - otrs2 2.3.4-6 (embed; bug #555267)
739 - webcalendar <unfixed> (embed; bug #555269)
740 - redmine 0.9.0~svn2907-1 (embed; bug #555270)
741 - jifty 0.90519-1 (embed; bug #555271)
742 - jquery <unfixed> (embed; bug #555272)
743 - passenger 2.2.5debian1-1 (embed; bug #555273)
744 - plone3 <unfixed> (embed; bug #555275)
745 - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
746 - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
747 - xulrunner <unfixed> (embed)
748 NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
749
750 gdb
751 - insight <unfixed> (embed)
752
753 e2fsprogs
754 - ldiskfsprogs <unfixable> (fork)
755
756 quazip (not packaged in Debian)
757 - qcake <unfixed> (embed)
758 NOTE: starting with upstream version 0.6.4
759
760 exo
761 - pcmanfm <unfixed> (embed; bug #499677)
762 NOTE: slightly modified source code
763
764 java
765 - openjdk-6 <unfixed>
766 - sun-java5 <unfixed>
767 - sun-java6 <unfixed>
768
769 libphp-snoopy
770 - ampache 3.4.1-2 (embed; bug #504169)
771 - gforge 4.6.99+svn6094-2 (embed)
772 - mahara 1.0.5-2 (embed; bug #504170)
773 - pixelpost 1.7.1-5 (embed; bug #504171)
774 - mediamate 0.9.3.6-5 (embed; bug #504172)
775 - opendb <removed> (embed; bug #504173)
776 [etch] - opendb <unfixed> (embed; bug #504173)
777 - wordpress 2.5.1-9 (embed; bug #443948)
778 - moodle <unfixed> (embed; bug #507185)
779 [etch] - phpgroupware <unfixed> (embed)
780 NOTE: phpgroupware-felamimail
781 - magpierss 0.72-3 (embed; bug #431089)
782
783 jquery
784 - zekr <unfixed> (embed)
785 - wordpress <unknown> (embed)
786 - yocto-reader <unfixed> (embed)
787 - textpattern <unfixed> (embed)
788 - genshi 0.5.1-1 (embed)
789 NOTE: compressed file under examples/ dir
790 - prewikka <unfixed> (embed)
791 - libramaze-ruby <unfixed> (embed)
792 - drupal5 <unfixed> (embed)
793 - b2evolution <unfixed> (embed)
794 - wesnoth <unfixed> (embed)
795
796 tablesorter (jquery plugin, not packaged yet)
797 - wesnoth <unfixed> (embed)
798
799 kses
800 - wordpress <unfixed> (embed; bug #504242)
801 NOTE: their copy has all methods renamed to wp_<foo>
802 NOTE: kses isn't in Debian, RFP: #504240
803 - moodle <unfixed> (embed; bug #507185)
804 - egroupware <unfixed> (embed)
805
806 magpierss
807 - wordpress <unfixed> (embed; bug #504242)
808 - moodle <unfixed>
809
810 php-gettext
811 - wordpress 2.8.4-1 (embed; bug #504242)
812
813 libphp-ixr (name may change, it is the Incutio XML-RPC)
814 - wordpress <unfixed> (embed; bug #504242)
815 NOTE: libphp-ixr isn't in Debian, RFP: #504236
816 - dokuwiki <unfixed> (embed)
817 - textpattern <unfixed> (embed)
818
819 libphp-cas
820 - glpi <unfixed> (embed)
821 - moodle <unfixed> (embed; bug #505984)
822
823 scriptaculous (prototype.js is among the embeds in the following)
824 - glpi <unfixed> (embed)
825 - libaws <unfixed> (embed; bug #555222)
826 - op-panel <unfixed> (embed)
827 - symfony <unfixed> (embed)
828 NOTE: maintainer says there are extra incompatible changes required
829 - pixelpost 1.7.1-6 (embed)
830 - webhelpers <unfixed> (embed)
831 - qwik <removed> (embed; bug #555241)
832 - smokeping <unfixed> (embed)
833 - turba2 <unfixed> (embed)
834 - typo3-src 4.2.3-1 (embed)
835 - request-tracker3.6 <unfixed> (embed)
836 - request-tracker3.8 <unfixed> (embed)
837 - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
838 - wordpress 2.5.0-2 (embed)
839 - libhtml-prototype-perl 1.48-3 (embed)
840
841 libmarkdown-php
842 - moodle <unfixed> (embed; bug #507185)
843 - pixelpost 1.7.1-6 (embed)
844
845 php-openid
846 - wordpress-openid <itp> (embed)
847
848 geshi
849 - dokuwiki 0.0.20080505-3.1 (embed)
850 - pgfouine 1.0-1.1 (embed)
851 - websvn 2.1.0-1 (embed)
852
853 webcalendar
854 - gforge 4.7~rc2-6 (embed; bug #504758)
855
856 libical
857 - kdepim <unfixed> (fork)
858 - kdepimlibs <unfixed> (fork)
859 NOTE: fixed in KDE4 post 4.1.x series
860 - claws-mail-extra-plugins <unfixed> (fork)
861
862 libltdl3
863 - kdelibs <unfixed> (embed)
864 NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
865 - synfig <unfixed> (embed)
866
867 harfbuzz
868 - qt4-x11 <unfixed> (embed)
869
870 libzip
871 - php5 <unfixed> (fork)
872 - odt2txt <unfixed> (embed; bug #523808)
873
874 json.php (not packaged; should be replaced with php's built-in functions)
875 - moodle <unfixed>
876 - yui <unfixed>
877 - gallery2 <unfixed>
878 - dokuwiki <unfixed>
879 - typo3-src <unfixed>
880
881 php-fpdf
882 - tcpdf <itp> (fork)
883 - moodle <unfixed>
884 - phpwiki <unfixed>
885 - egroupware <unfixed>
886 - ldap-account-manager <unfixed> (fork)
887
888 tcpdf (itp: #495985)
889 - moodle <unfixed>
890 - phpmyadmin <unfixed>
891
892 typo3
893 - moodle <unfixed>
894
895 spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
896 - moodle <unfixed>
897 - gosa <unfixed>
898
899 php-ole (itp: #487558)
900 - moodle <unfixed>
901
902 pieforms (http://www.catalyst.net.nz)
903 - mahara <unfixed>
904
905 savant2 (http://phpsavant.com)
906 - egroupware <unfixed>
907
908 rssparser (http://nwow.org)
909 - egroupware <unfixed>
910 - phpgroupware <unfixed>
911
912 lcms
913 - openjdk-6 <unfixed> (fork)
914
915 libphp-phplayersmenu
916 - diogenes <unfixed>
917 - phpldapadmin <unfixed>
918
919 libphp-pclzip
920 - docvert <unfixed>
921 - moodle <unfixed>
922 - egroupware <unfixed>
923
924 libphp-simplepie
925 - dokuwiki <unfixed>
926
927 libphp-jpgraph
928 - egroupware <unfixed>
929
930 php-simpletest
931 - moodle <unfixed>
932
933 libpng
934 - iceweasel <not-affected> (uses xulrunner)
935 - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
936 - iceape 1.0.13~pre080614i-0etch1 (embed)
937 - xulrunner 1.9.0.13-1 (embed)
938 [lenny] - xulrunner 1.9.0.11-0lenny1
939 [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
940 - gamera 3.2.3-1 (embed)
941
942 irssi
943 - silc-client <unfixed> (embed)
944 NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
945
946 extc
947 - mtasc <unfixed> (embed)
948 - haxe <unfixed> (embed)
949
950 swflib
951 - mtasc <unfixed> (embed)
952 - haxe <unfixed> (embed)
953
954 libitext-java
955 - bouncycastle 2.1.4-1 (embed)
956
957 python-ply
958 - pyke <unfixed> (embed; bug #555363)
959 - pywbem <unfixed> (embed; bug #555364)
960 - sepolgen <unfixed> (embed; bug #555365)
961 - zope-textindexng3 <unknown> (embed)
962 - iceweasel <not-affected> (uses xulrunner)
963 - xulrunner <unknown> (embed)
964 - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
965
966 libdumbnet (libdnet upstream)
967 - nmap <unfixed> (fork)
968
969 gcc-4.4
970 - gcc-mingw32 <unfixed> (embed)
971
972 camlimages
973 - advi <unfixed> (static; bug #550441)
974
975 memcached
976 - memcachedb <unfixed> (embed)
977
978 yajl
979 - argyll <unfixed> (embed; bug #544223)
980 NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
981
982 nusoap
983 - gforge 4.8.2-1 (embed)
984
985 libept
986 - adept <unfixed> (embed; bug #540649)
987
988 libvorbis
989 - iceweasel <not-affected> (uses xulrunner)
990 - xulrunner <unfixed> (embed; bug #540959)
991 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
992 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
993 - iceape <unfixed> (embed)
994 [etch] - iceape <not-affected> (introduced in 2.0)
995 [lenny] - iceape <not-affected> (introduced in 2.0)
996
997 cairo
998 - iceweasel <not-affected> (uses xulrunner)
999 - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1000
1001 liboggz
1002 - iceweasel <not-affected> (uses xulrunner)
1003 - xulrunner <unfixed> (embed; bug #540959)
1004 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1005 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1006 - iceape <unfixed> (embed)
1007 [etch] - iceape <not-affected> (introduced in 2.0)
1008 [lenny] - iceape <not-affected> (introduced in 2.0)
1009
1010 liboggplay
1011 - iceweasel <not-affected> (uses xulrunner)
1012 - xulrunner <unfixed> (embed; bug #540959)
1013 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1014 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1015 - iceape <unfixed> (embed)
1016 [etch] - iceape <not-affected> (introduced in 2.0)
1017 [lenny] - iceape <not-affected> (introduced in 2.0)
1018
1019 php-net-dnsbl
1020 - serendipity <unfixed> (embed)
1021
1022 php-onyx-rss
1023 - serendipity <unfixed> (embed)
1024
1025 php-text-wiki
1026 - serendipity <unfixed> (embed)
1027
1028 php-xml-rpc
1029 - serendipity <unfixed> (embed)
1030
1031 polarssl (does not have a shared library)
1032 - pdkim <itp> (embed; bug #543150)
1033 - xyssl <unfixed> (old-version)
1034
1035 pidgin
1036 - gaim <removed> (old-version)
1037 - qutecom <unfixed> (embed; bug #559785)
1038
1039 icu
1040 - webkit 1.0.1-1 (embed; bug #547214)
1041 - texlive-bin <unfixed> (fork)
1042 NOTE: texlive upstream working with icu upstream to merge their changes
1043
1044 cyrus-imapd-2.2
1045 - kolab-cyrus-imapd <unfixed> (fork)
1046 - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1047
1048 python-cxx-dev
1049 - freecad 0.9.2646.3-1 (embed; bug #547936)
1050
1051 zipios++
1052 - freecad 0.9.2646.3-1 (embed; bug #547941)
1053 - enigma 0.92.3-3 (embed)
1054 NOTE: likely fixed earlier, marking etch's version as fixed
1055
1056 linux-2.6
1057 - kvm <unfixed> (embed; bug #549973) [./kernel/*]
1058 - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1059 - kernel-source-2.6.8 <removed> (old-version)
1060 - kernel-source-2.4.27 <removed> (old-version)
1061 - kernel-source-2.4.24 <removed> (old-version)
1062 - kernel-source-2.2.25 <removed> (old-version)
1063 - kernel-source-2.2.20 <removed> (old-version)
1064
1065 libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1066 - kvm <unfixed> (embed) [./libfdt/*]
1067
1068 qweb (not packaged)
1069 - ajaxterm <unfixed>
1070
1071 opensaml2
1072 - opensaml <removed> (old-version)
1073
1074 shibboleth-sp2
1075 - shibboleth-sp <removed> (old-version)
1076
1077 tuxonice-userui
1078 - suspend2-userui <removed> (old-version)
1079
1080 expat
1081 - w3c-libwww <removed> (embed; bug #551941)
1082 [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1083 - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1084 - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1085 - python2.4 <unfixable> (embed; bug #553403)
1086 - python-4suite <unfixed> (embed; bug #516935)
1087 - wxwindows2.4 <removed> (embed)
1088 - wxwidgets2.6 2.6.3.2.2-4 (embed)
1089 - wxwidgets2.8 2.8.10.1-2 (embed)
1090 - celementtree <unfixed> (embed)
1091 - audacity 1.3.2-1 (embed)
1092 - matanza <unfixed> (embed)
1093 - tdom <unfixed> (embed)
1094 - udunits <unfixed> (embed)
1095 - apr-util 1.2 (embed)
1096 - ayttm <unfxed> (embed; bug #561006)
1097 - cableswig <unfixed> (embed)
1098 - cadaver <unfixed> (embed)
1099 - cmake 2.6.0-6 (embed)
1100 - coin3 <unfixed> (embed)
1101 - gdcm 2.0.14-2 (embed)
1102 - ghostscript <unfixed> (embed)
1103 - grmonitor <unfixed> (embed)
1104 - iceape <unfixed> (embed)
1105 - insighttoolkit <unfixed> (embed)
1106 - libparagui1.1 <unfixed> (embed)
1107 - paraview <unfixed> (embed)
1108 - poco <unfixed> (embed)
1109 - simgear <unfixed> (embed)
1110 - sitecopy <unfixed> (embed)
1111 - smart 1.0-1 (embed)
1112 [etch] - smart <unfixed> (embed)
1113 - swish-e <unfixed> (embed)
1114 - tla <unfixed> (embed)
1115 - vtk <unfixed> (embed)
1116 - wbxml2 <unfixed> (embed)
1117 - xmlrpc-c <unfixed> (embed)
1118 - iceweasel <unfixed> (embed)
1119 - kompozer <unfixed> (embed)
1120 - vxl 1.13.0-2 (embed)
1121 - xulrunner <unfixed> (embed)
1122 - apache2 2.2 (embed)
1123 - texlive-bin <unfixed> (embed) [included twice]
1124 - vnc4 <unfixed> (embed)
1125 - xotcl <unfixed> (embed)
1126
1127 xerces-c
1128 - xerces-c2 <unfixed> (old-version)
1129 - xerces27 <removed> (old-version)
1130
1131 md5 (RSA's version; not the gnu version provided by coreutils)
1132 - w3c-libwww <removed> (embed; bug #551942)
1133 [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1134
1135 enet
1136 - sauerbraten <unfixed> (embed; #497194)
1137
1138 eglibc
1139 - glibc <removed> (old-version)
1140
1141 galib
1142 - gamera 3.2.3-1 (embed)
1143
1144 configobj
1145 - bzr <unfixed> (embed; bug #555336)
1146 - elisa <unfixed> (embed; bug #555337)
1147 - gaupol <unfixed> (embed; bug #555338)
1148 - ipython <unfixed> (embed; bug #555339)
1149 - pida <unfixed> (embed; bug #555340)
1150 - psychopy <unfixed> (embed; bug #555341)
1151 - rest2web <unfixed> (embed; bug #555342)
1152 - auth2db <unknown> (embed)
1153 - dynagen <unknown> (embed)
1154 - iceweasel <unknown> (embed)
1155 - sabnzbdplus <unknown> (embed)
1156 - xulrunner <unknown> (embed)
1157 - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1158
1159 python-clientform
1160 - bibus <unfixed> (embed; bug #555332)
1161 - zope2.10 <unfixed> (embed; bug #555333)
1162 - zope2.11 <unfixed> (embed; bug #555334)
1163 - python-mechanize <unknown> (embed)
1164 - twill <unknown> (embed)
1165
1166 python-mechanize
1167 - zope2.10 <unfixed> (embed; bug #555337)
1168 - zope2.11 <unfixed> (embed; bug #555338)
1169 - twill <unknown> (embed; bug #555339)
1170
1171 pexpect
1172 - duplicity 0.6.06-1 (embed; bug #555361)
1173 - hplip <unfixed> (embed; bug #555362)
1174 - smart <unfixed> (embed; bug #555363)
1175
1176 pyparsing
1177 - bauble <unfixed> (embed; bug #555366)
1178 - boa-constructor 0.6.1-8 (embed; bug #555367)
1179 - calibre <unfixed> (embed; bug #555368)
1180 - matplotlib <unfixed> (embed; bug #531024)
1181 - zhpy <unfixed> (embed; bug #555370)
1182 - polybori <unknown> (embed)
1183 - python-whoosh <unknown> (embed)
1184 - twill <unknown> (embed)
1185 - zope-textindexng3 <unknown> (embed)
1186
1187 python-pysqlite2
1188 - python2.4 <unfixed> (embed; bug #553403)
1189 - python2.5 <unfixed> (embed; bug #553403)
1190
1191 celementtree
1192 - python2.5 <unfixed> (embed)
1193 - smart 1.0-1 (embed)
1194 [etch] - smart <unfixed> (embed)
1195
1196 elementtree
1197 - python2.5 <unfixed> (embed)
1198 - bzr <unfixed> (embed; bug #555343)
1199 - gedit 2.28.2-1 (embed; bug #555344)
1200 - smart 1.0-1 (embed)
1201 [etch] - smart <unfixed> (embed)
1202 - solfege <unfixed> (embed; bug #555345)
1203 - w3af <unfixed> (embed; bug #555346)
1204 - python-qt4 <unknown> (embed)
1205 - sphinx <unknown> (embed)
1206 - python-nltk <itp> (embed)
1207
1208 python2.5
1209 - python2.4 <unfixed> (old-version)
1210 - jython <unfixed> (embed)
1211 NOTE: embeds many stdlib modules
1212 - python-django <unfixed> (embed; bug #555419)
1213 NOTE: embeds stdlib modules: doctest, decimal
1214 - gamera 3.2.3-1 (embed)
1215 NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1216 - boa-constructor <unfixed> (embed; bug #555426)
1217 NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1218 - nicotine <unfixed> (embed; bug #555427)
1219 NOTE: embeds stdlib modules: ConfigParser
1220 - museek+ <unfixed> (embed; bug #555428)
1221 NOTE: embeds stdlib modules: ConfigParser
1222 - vegastrike-data <unfixed> (embed)
1223 NOTE: embeds many stdlib modules
1224 - codespeak-lib 1.1.1-1 (embed; bug #555420)
1225 NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1226 - config-manager <unfixed> (embed; bug #555423)
1227 NOTE: embeds stdlib modules: optparse
1228 - jhbuild 2.28.0-1 (embed; bug #555421)
1229 NOTE: embeds stdlib modules: optparse, subprocess
1230 - smart <unfixed> (embed; bug #555432)
1231 NOTE: embeds stdlib modules: optparse
1232 - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1233 NOTE: embeds stdlib modules: doctest
1234 - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1235 NOTE: embeds stdlib modules: doctest
1236 - distribute <unfixed> (embed)
1237 NOTE: embeds stdlib modules: doctest
1238 - python-setuptools <unfixed> (embed; bug #555435)
1239 NOTE: embeds stdlib modules: doctest
1240 - zope.testing <unfixed> (embed; bug #555436)
1241 NOTE: embeds stdlib modules: doctest
1242 - translate-toolkit <unfixed> (embed; bug #555422)
1243 NOTE: embeds stdlib modules: textwrap, contextlib
1244 - libtpclient-py <unfixed> (embed; bug #555424)
1245 NOTE: embeds stdlib modules: subprocess
1246 - grass <unfixed> (embed; bug #555425)
1247 NOTE: embeds stdlib modules: subprocess
1248 - coherence <unfixed> (embed; bug #555429)
1249 NOTE: embeds stdlib modules: uuid
1250 - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1251 NOTE: embeds stdlib modules: uuid
1252 - setroubleshoot <unfixed> (embed; bug #555431)
1253 NOTE: embeds stdlib modules: uuid
1254 - linkchecker <unfixed> (embed; bug #555414)
1255 NOTE: embeds msgfmt.py script
1256 - imdbpy <unfixed> (embed)
1257 NOTE: embeds msgfmt.py script
1258 - kiwi <unfixed> (embed)
1259 NOTE: embeds msgfmt.py script
1260 - moin <unfixed> (embed)
1261 NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1262 - plone3 <unfixed> (embed)
1263 NOTE: embeds msgfmt.py script
1264 - roundup <unfixed> (embed)
1265 NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1266 - rednotebook <unfixed> (embed; bug #555415)
1267 NOTE: embeds msgfmt.py script
1268 - turbogears <unfixed> (embed)
1269 NOTE: embeds msgfmt.py script
1270 - elisa <unfixed> (embed)
1271 NOTE: embeds msgfmt.py script, stdlib modules: uuid
1272 - calibre <unfixed> (embed)
1273 NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1274 - mailman <unfixed> (embed; #555416)
1275 NOTE: embeds msgfmt.py script
1276 - python-docutils <unknown> (embed)
1277 NOTE: embeds stdlib modules: optparse, textwrap
1278 - python-imaging <unknown> (embed)
1279 NOTE: embeds stdlib modules: doctest
1280 - python-mechanize <unknown> (embed)
1281 NOTE: embeds stdlib modules: doctest
1282 - twill <unknown> (embed)
1283 NOTE: embeds stdlib modules: subprocess
1284 - zeroc-ice <unknown> (embed)
1285 NOTE: embeds stdlib modules: subprocess
1286 - wxwidgets2.8 <unknown> (embed)
1287 NOTE: embeds stdlib modules: subprocess
1288 - cycle <unknown> (embed)
1289 NOTE: embeds msgfmt.py script
1290 - deluge <unknown> (embed)
1291 NOTE: embeds msgfmt.py script
1292 - opendict <unknown> (embed)
1293 NOTE: embeds msgfmt.py script
1294 - openerp-client <unknown> (embed)
1295 NOTE: embeds msgfmt.py script
1296 - rapidsvn <unknown> (embed)
1297 NOTE: embeds msgfmt.py script
1298 - wammu <unknown> (embed)
1299 NOTE: embeds msgfmt.py script
1300 - gaphor <unknown> (embed)
1301 NOTE: embeds msgfmt.py script
1302 - pida <unknown> (embed)
1303 NOTE: embeds msgfmt.py script
1304 - python-formencode <unknown> (embed)
1305 NOTE: embeds msgfmt.py script
1306 - duplicity <unfixed> (embed)
1307 NOTE: embeds stdlib module: urlparse, tarfile
1308 - pygopherd <unfixed> (embed)
1309 NOTE: embeds stdlib module: zipfile
1310
1311 argparse
1312 - twill <unfixed> (embed; bug #555347)
1313 - ipython <unfixed> (embed; bug #555348)
1314
1315 coherence
1316 - elisa <unfixed> (embed; bug #555335)
1317
1318 simpletal
1319 - plastex <unfixed> (embed; bug #555371)
1320
1321 flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1322 - postr <unfixed> (embed)
1323 - elisa <unfixed> (embed)
1324
1325 simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1326 - apertium-tolk <unfixed> (embed)
1327 - ipython <unfixed> (embed)
1328 - virtaal <unfixed> (embed)
1329
1330 distribute
1331 - setuptools <removed> (old-version)
1332
1333 rails
1334 - jruby1.2 <unfixed> (embed) [./bench/rails/*]
1335 - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1336 - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1337 - thin <unfixed> (embed) [./spec/rails_app/*]
1338 NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1339 NOTE: be dangerous if developers are naively basing their code off of the examples
1340 NOTE: prototype.js is among the example files
1341
1342 lucene2 (prototype.js is among the embeds in the following)
1343 - lucene <unfixed> (old-version)
1344 - pylucene <unfixed> (embed)
1345 - libpdfbox-java <unfixed> (embed)
1346 - libfontbox-java <unfixed> (embed)
1347 - libjempbox-java <unfixed> (embed)
1348 - solr <unfixed> (embed)
1349
1350 unicode-data
1351 - syslinux <unfixed> (embed)
1352 - camomile <unfixed> (embed)
1353 - fribidi <unfixed> (embed)
1354 - m17n-db <unfixed> (embed)
1355 - sbcl <unfixed> (embed)
1356 - heimdal <unfixed> (embed)
1357 - icu <unfixed> (embed)
1358 - icu4j <unfixed> (embed)
1359 - krb5 <unfixed> (embed)
1360 - moodle <unfixed> (embed)
1361 - openldap <unfixed> (embed)
1362 - pike7.6 <unfixed> (embed)
1363 - samba <unfixed> (embed)
1364 - samba4 <unfixed> (embed)
1365 - cmucl <unfixed> (embed)
1366 - typo3-src <unfixed> (embed)
1367 - mauve <unfixed> (embed)
1368 - texlive-bin <unfixed> (embed)
1369 - ypsilon <unfixed> (embed)
1370 - jeuclid <unfixed> (embed)
1371 - charmap.app <unfixed> (embed)
1372 - clisp <unfixed> (embed)
1373 - gnulib <unfixed> (embed)
1374 - opensrs-client <unfixed> (embed)
1375 - saxonb <unfixed> (embed)
1376 - rails <unfixed> (embed)
1377
1378 feedparser
1379 - rawdog <unfixed> (embed; bug #383422)
1380 - miro <unfixed> (embed; bug #555351)
1381 - calibre <unfixed> (embed; bug #555352)
1382 - freevo <unfixed> (embed; bug #555353)
1383 - pida <unfixed> (embed; bug #555354)
1384 - planet-venus <unfixed> (embed; bug #555355)
1385 - plone3 <unfixed> (embed; bug #555356)
1386 - exaile 0.2.14+debian-1 (embed)
1387 - screenlets 0.1.2-3 (embed)
1388 NOTE: included twice
1389
1390 agg:
1391 - matplotlib <unfixed> (embed: bug #377271)
1392 - contextfree <unfixed> (embed)
1393 NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1394 - exactimage <unfixed> (embed)
1395 - python-enable <unfixed> (embed)
1396 - mapnik 0.5.1-3 (embed)
1397 NOTE: links statically to agg, but shared library is not available (bug #377271)
1398
1399 vtk
1400 - paraview <unfixable> (embed; bug #495426)
1401
1402 txt2tags
1403 - rednotebook <unfixed> (embed)
1404
1405 htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1406 - gajim <unfixed> (embed)
1407 - emesene <unfixed> (embed)
1408 - convirt <unfixed> (embed)
1409 - pida <unfixed> (embed)
1410 - rednotebook <unfixed> (embed)
1411
1412 horde3 (prototype.js is among the embeds in the following)
1413 - mnemo2 <unfixed> (embed)
1414 - nag2 <unfixed> (embed)
1415
1416 cimg
1417 - gmic <itp> (embed)
1418
1419 mootools
1420 - gmic <itp> (embed)
1421
1422 openldap
1423 - openldap2.3 <removed> (old-version)
1424
1425 grub2
1426 - grub <unfixed> (old-version)
1427
1428 gnupginterface
1429 - duplicity <unfixed> (embed)
1430
1431 python-dateutil
1432 - awn-extras-applets <unfixed> (embed)
1433 - matplotlib <unknown> (embed)
1434
1435 cups
1436 - cupsys <removed> (old-version)
1437
1438 yui
1439 - bcfg2 <not-affected> (present in source but not included in any binary files)
1440 - serendipity <unfixed> (embed; bug #557746)
1441 - moodle 1.8.2.dfsg-5 (embed)
1442 - jifty 0.91117-1 (embed; bug #557748)
1443 - webgui 7.7.26-1 (embed)
1444 - loggerhead 1.17-1 (embed)
1445
1446 quake3 (vanilla source not packaged in debian)
1447 - openarena <unfixable> (fork)
1448
1449 quake2 (vanilla source not packaged in debian)
1450 - alien-arena <unfixable> (fork)
1451 - warsow <unfixable> (fork)
1452
1453 libtheora
1454 - iceweasel <not-affected> (uses xulrunner)
1455 - xulrunner <unfixed> (embed; bug #540959)
1456 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1457 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1458 - iceape <unfixed> (embed; bug #559276)
1459 [etch] - iceape <not-affected> (introduced in iceape 2.0)
1460 [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1461
1462 dtoa
1463 - bfilter <unfixed> (embed)
1464 - cacao <unfixed> (embed)
1465 - cdrdao <unfixed> (embed)
1466 - classpath <unfixed> (embed)
1467 - freej <unfixed> (embed)
1468 - iceape <unfixed> (embed)
1469 - iceweasel <unfixed> (embed)
1470 - jscoverage <unfixed> (embed)
1471 - kde4libs <unfixed> (embed)
1472 - kdelibs <unfixed> (embed)
1473 - kompozer <unfixed> (embed)
1474 - libv8 <unfixed> (embed)
1475 - mono <unfixed> (embed)
1476 - newlib <unfixed> (embed)
1477 - nspr <unfixed> (embed)
1478 - php5 <unfixed> (embed)
1479 - polyml <unfixed> (embed)
1480 - qt4-x11 <unfixed> (embed)
1481 - rhino <unfixed> (embed)
1482 NOTE: code translated to Java
1483 - ruby1.8 <unfixed> (embed)
1484 - ruby1.9 <unfixed> (embed)
1485 - ruby1.9.1 <unfixed> (embed)
1486 - sdd <unfixed> (embed)
1487 - sfind <unfixed> (embed)
1488 - star <unfixed> (embed)
1489 - tinymux <unfixed> (embed)
1490 - virtualbox-ose <unfixed> (embed)
1491 - webkit <unfixed> (embed)
1492 - xulrunner <unfixed> (embed)
1493
1494 ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1495 - firegpg <unfixed> (embed)
1496 - enigmail <unfixed> (embed)
1497
1498 ptmalloc (not packaged in Debian)
1499 - crystalspace <unfixed> (embed)
1500 - qt4-x11 <unfixed> (embed)
1501
1502 svgalib
1503 - usplash <unfixed> (embed)
1504
1505 bogl
1506 - usplash <unfixed> (embed)
1507
1508 taglist
1509 - usplash <unfixed> (embed)
1510
1511 portaudio
1512 - audacity <unfixed> (embed; bug #323711)
1513
1514 nyquist
1515 - audacity <unfixed> (embed)
1516 NOTE: embeds a forked nyquist with support for a shared library
1517
1518 vamp-plugin-sdk
1519 - audacity <unfixed> (embed)
1520
1521 wordpress
1522 - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1523
1524 php5
1525 - php4 <removed> (old-version)
1526
1527 classpath
1528 - libgnucrypto-java <unfixed> (embed; bug #559788)
1529
1530 libtool
1531 - apr <unfixed> (static; bug #489625)
1532 NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1533 - arts <unfixed> (embed)
1534 - bochs <unfixed> (embed; bug #560884)
1535 - camserv <unfixed> (embed)
1536 - collectd <unfixed> (embed)
1537 - courier-authlib <unfixed> (embed)
1538 - cvsnt <unfixed> (embed)
1539 - dico <not-affected> (Uses the system copy of ltdl)
1540 - freeradius 0.1+20010527-1 (embed)
1541 NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1542 - ggobi <unfixed> (embed)
1543 - glame <unfixed> (embed)
1544 - gnash <unfixed> (embed)
1545 - gnu-smalltalk <unfixed> (embed)
1546 - google-gadgets <unfixed> (embed)
1547 - graphicsmagick 1.3.5-6 (embed)
1548 - graphviz 2.8-3 (embed)
1549 NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1550 - guile-1.6 <unfixed> (embed)
1551 - hamlib <unfixed> (embed)
1552 - hercules <unfixed> (embed)
1553 - jags 1.0.4-3 (embed; bug #560864)
1554 - kdelibs <unfixed> (embed)
1555 - libannodex <removed> (embed)
1556 - libextractor <unfixed> (embed)
1557 - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1558 - libtunepimp <unfixed> (embed)
1559 - mp4h <unfixed> (embed)
1560 - naim <unfixed> (embed)
1561 - parser-mysql <unfixed> (embed)
1562 - pinball <unfixed> (embed)
1563 - redland <unfixed> (embed)
1564 - siproxd <unfixed> (embed)
1565 - ski <unfixed> (embed)
1566 - synfig <unfixed> (embed)
1567 - unixodbc 2.2.4-5 (embed)
1568 - xmlsec1 1.2.14-1 (embed)
1569 - clamav <unfixed> (embed)
1570 - imagemagick <unfixed> (embed)
1571 - hypre 2.4.0b-5 (embed)
1572 - lam <unfixed> (embed)
1573 - openmpi <unfixable> (embed; bug #559386)
1574 - parser <unfixed> (embed)
1575 - pdsh <unfixed> (embed; bug #560892)
1576 - sbnc 1.2-8 (embed)
1577 - sdcc <unfixed> (embed)
1578 - wml <unfixed> (embed)
1579 - proftpd-dfsg <unfixed> (embed)
1580 - babel 1.4.0.dfsg-5 (embed)
1581 - libprelude <unfixed> (embed)
1582 - heartbeat 2.1.4-7 (embed)
1583 NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1584 NOTE: might've been fixed earlier
1585 - gcc-* <unknown> (embed)
1586
1587 ocamlgsl
1588 - orpie 1.5.1-7.1 (embed; bug #550058)
1589
1590 xdotool
1591 - keynav <unfixed> (embed; bug #560103)
1592
1593 bulletphysics (not packaged; http://www.bulletphysics.org/)
1594 - supertuxkart <unfixed> (embed)

  ViewVC Help
Powered by ViewVC 1.1.5