/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Contents of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log


Revision 13718 - (show annotations) (download)
Tue Jan 5 06:44:56 2010 UTC (3 years, 4 months ago) by geissert
File size: 47760 byte(s)
record serendipity's embeds br
1 Embedded code copies
2 ====================
3
4 This file collects source packages that embed code from other projects.
5 This is considered bad for fixing security flaws because the fix needs
6 to be applied in multiple source packages.
7
8 Format:
9 <srcpkg> (<optional comment about srcpkg>)
10 - <embedding srcpkg> <status> (<sort>; bug #<number>)
11 NOTE: optional comments about the linkage of the embedding srcpkg
12
13 status: version number fixing the embedded copy, <unfixed>, <removed>,
14 <itp>, <not-affected>, <unknown> if the version number can not
15 be determined, or <unfixable> for unavoidable cases (e.g., forks
16 that add real value)
17 sort: static (linking statically against a lib)
18 embed (embeds a copy of the library into another source package)
19 modified-embed (embeds a code copy that differs from upstream code)
20 fork (a full-blown fork of another source package)
21 old-version (an older version of essentially the same code)
22
23 The srcpkg might be some string to identify the code if there is no
24 specific source package.
25
26 Everything up to the next line is ignored.
27 ---BEGIN
28 xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29 NOTE: Fixed packages link to poppler library unless otherwise noted
30 - pdftohtml <unknown>
31 [sarge] - pdftohtml <unfixed>
32 [etch] - pdftohtml <unfixed>
33 NOTE: has been replaced by poppler-utils
34 - kdegraphics 4:4.2.2-1 (embed; bug #436164)
35 - texlive-base 3.0-12 (embed)
36 - texlive-bin 2007-1 (embed)
37 NOTE: links to poppler
38 - koffice <unfixed> (embed; bug #436163)
39 - libextractor 0.5.12-1 (embed)
40 NOTE: libextractor is using its own pdf decoder now
41 - ipe <unfixed> (embed)
42 NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
43 - ruby-gnome2 <unknown> (embed)
44 NOTE: copy only present in source but links to poppler
45 - pdfedit <unfixed> (embed; bug #510794)
46 - swftools <unfixed> (embed; bug #551293)
47 - poppler <unfixable> (fork)
48
49 ppmd
50 - libcomplearn-mod-ppmd <unfixed> (fork)
51 NOTE: discussion in #458152
52
53 libevent
54 - transmission 1.71-1 (embed; bug #529372)
55
56 lrmi
57 - read-edid 2.0.0-1 (embed; bug #495131)
58 - s3switch <unfixed> (embed)
59 - xresprobe <unfixed> (embed)
60 - zhcon <unfixed> (embed)
61
62 peercast
63 - gnome-peercast <removed> (embed)
64 [etch] - gnome-peercast <unfixed> (embed)
65
66 silc-toolkit
67 - silc-client 1.1~beta6-1 (embed)
68
69 icclib
70 - ghostscript <unfixed> (embed)
71 - argyll <unfixed> (embed)
72
73 dietlibc
74 - ccontrol 0.9.1+20071204-1 (static)
75
76 libmikmod
77 - sdl-mixer1.2 <unfixed> (embed)
78 TODO: report bug
79
80 libiax
81 - iaxmodem <unfixable> (embed; bug #548885)
82
83 spandsp
84 - iaxmodem <unfixable> (embed; bug #548885)
85
86 zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
87 - dpkg <unfixed> (static)
88 NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
89 - rsync <unfixed> (embed)
90 NOTE: somehow derived code base
91 - mono <unfixed> (embed)
92 TODO: check mozilla
93 - Linux kernels <unfixed> (embed)
94 - pvpgn 1.7.8-2 (embed)
95 - mrtg 2.12.2-1 (embed)
96 - rpm <unknown> (embed)
97 NOTE: pinged anibal since when rpm was fixed
98 - tuxcmd-modules <unfixed> (embed)
99 - zsync <unfixed>
100 - tra <unfixed>
101 - sash <unfixed>
102 - nsis <unfixed>
103 - mseide-msegui <unfixed>
104 NOTE: mseide
105 - mirrordir <unfixed>
106 - poco <unfixed>
107 - klibc <unfixed>
108 - ghostscript <unfixed>
109 - freeimage <unfixed>
110 - clamav <unfixed> (fork)
111 NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
112 - tuxonice-userui <unfixed>
113 - plt-scheme <unfixed>
114 - perl <unfixed>
115 - paraview <unfixed>
116 - gcvs <unfixed>
117 - dump <unfixed>
118 - aide <unfixed> (static)
119 - dar <unfixed> (static)
120 - avfs <unfixed>
121 - fpc <unfixed>
122 - winff <unfixed>
123 NOTE: inherited from fpc, see #472304
124 - lazarus <unfixed>
125 NOTE: inherited from fpc, see #472304
126 - erlang <unfixed> (embed)
127 - gamera 3.2.3-1 (embed)
128 - python2.4 <unfixed> (embed; bug #553403)
129 - python2.5 <unfixed> (embed; bug #553403)
130
131 dulwich
132 - hg-git 0.1.0-1 (embed; bug #541996)
133
134 libvigraimpex
135 - hugin <unfixed> (embed; bug #542259)
136 - enblend-enfuse <unfixed> (embed; bug #542258)
137 - gamera 3.2.3-1 (embed)
138
139 libbz2
140 - dpkg <unfixed> (static)
141
142 libgadu
143 - centerim <unfixed> (embed; bug #559783)
144 - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
145 - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
146 - kdenetwork 4:3.3.2-5 (embed)
147 NOTE: from kdenetwork: kopete
148 - ekg 1:1.8~rc0-1 (embed)
149 - kadu 0.6.0.2-3 (embed; bug #504430)
150 - gadu <itp> (embed)
151
152 xmlrpc (which package is the "origin" of this code?)
153 - drupal <unfixed> (embed)
154 - phpgroupware <unfixed> (embed)
155 - egroupware <unfixed> (embed)
156 - phpwiki <unfixed> (embed)
157 - php4 <unfixed> (embed)
158 TODO: check, php-pear, IIRC this was reorganized some weeks ago?
159
160 shtool (affects build-time only)
161 - mysql-ocaml <unfixed> (embed)
162 - php4 <unfixed> (embed)
163
164 xulrunner
165 - iceape <unfixed> (embed; bug #561749)
166 - iceweasel 2.0.0.19 (embed)
167 - icedove <unfixed> (embed; bug #561750)
168 - kompozer <unfixed> (embed; bug #532168)
169 - galeon 2.0.2-4 (embed)
170 - epiphany-browser 2.14.3-8 (embed)
171 - conkeror 0.9~git080629-2 (embed)
172 - kazehakase 0.4.2-1 (embed)
173
174 xli
175 - xloadimage <unfixed> (embed)
176
177 lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
178 - openmotif <unfixed> (embed)
179 - libxpm <unfixed> (embed)
180
181 kerberized apps with BSD origin
182 - krb4 <removed> (embed)
183 - krb5 <unfixed> (embed)
184 - heimdal <unfixed> (embed)
185
186 grip (which pkg is the origin?)
187 - libcdaudio <unfixed>
188 - grip <unfixed>
189 - gnome-vfs <unfixed>
190 TODO: check vfs2 as well
191
192 fudforum
193 [etch] - phpgroupware <unfixed> (embed)
194 NOTE: phpgroupware-fudforum
195 [sarge] - egroupware-fudforum <removed> (embed)
196
197 libbsd
198 - rdate 1:1.2-3 (embed)
199 - atheme-services <unfixed>
200 - libbsd-arc4random-perl <unfixed>
201 - isakmpd <unfixed>
202 - bsdgames <unfixed> (embed)
203 - bsd-mailx <unfixed> (embed)
204 - netcat-openbsd <unfixed> (embed; bug #550611)
205 - openssh <unfixed> (embed)
206 - unworkable <unfixed> (embed)
207
208 cvs
209 - gcvs <unfixed> (embed)
210 NOTE: see cvsunix/src in tarball
211
212 pcre3
213 - php4 <unknown> (embed)
214 - analog 2:5.23-0woody1 (embed)
215 - goffice <unfixed> (embed)
216 NOTE: libgoffice-*
217 - vfu 4.06-4.1 (embed; bug #450754)
218 - tf5 5.0beta7-1 (embed)
219 - monotone 0.43-1 (embed)
220 NOTE: this only affects versions >= 0.37
221 - glib2.0 2.15.2-1 (embed)
222 - apache2 2.0.53-4 (embed)
223 - exim4 4.10-0.srh20.12 (embed)
224 - yacas <unfixed> (embed)
225 NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
226 - gtamsanalyzer.app 0.42-5 (embed)
227 - tin 980117-1 (embed)
228 - kazehakase 0.5.2-1
229 - webkit 1.0.1-1 (embed)
230 - qt4-x11 <unfixed> (embed)
231 NOTE: embedded via webkit copy
232 - erlang <unfixed> (embed)
233 - ssed <unfixed> (embed)
234
235 tiff
236 - wxwindows2.4 2.2.1 (embed)
237 - gamera 3.2.3-1 (embed)
238
239 uudeview
240 - libconvert-uulib-perl <unfixed> (embed)
241 - pan <unfixed> (embed)
242
243 sqlite (not affected by security vulnerabilities so far)
244 - amarok <unfixed> (embed)
245 - monotone 0.43-1 (embed)
246 - iceweasel <unfixed> (embed)
247 - heimdal <unfixed> (embed; bug #559616)
248
249 util-linux/mount
250 - loop-aes-utils <unfixed> (embed)
251 NOTE: contains code from util-linux' mount in the mount-aes-udeb
252
253 sylpheed
254 - sylpheed-claws <unfixed> (fork)
255
256 phpsysinfo
257 - egroupware <unfixed> (embed)
258 - phpgroupware <unfixed> (embed)
259
260 phpldapadmin
261 [sarge] - egroupware <unfixed> (embed)
262 NOTE: removed from egroupware after sarge
263
264 chmlib
265 - kchmviewer <unknown> (embed)
266
267 ffmpeg (libavcodec/libavformat)
268 - mplayer 1.0~rc2-14 (embed; bug #395252)
269 - kino 1.0.0-1
270 - vlc <not-affected> (Links dynamically since initial release)
271 - smilutils 0.3.0-10
272 NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
273 - motion 3.1.19-1
274 - gstreamer0.10-ffmpeg 0.10.3-2
275 - xmovie <removed> (static)
276 TODO: gimp-gap (potentially using ffmpeg code as well)
277 - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
278 - audacity 1.3.7-2 (embed; bug #512278)
279
280 faad2
281 - mplayer 1.0~rc2-20 (embed)
282 - avifile <unfixed> (embed; bug #538750)
283 - ffmpeg-debian <removed> (old-version)
284
285 libmad (MPEG decoding lib)
286 - xine-lib <unfixed> (embed)
287 - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
288 TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
289
290 libdts
291 - xine-lib <unfixed> (embed)
292
293 flac
294 - xine-lib <unfixed> (embed)
295
296 liba52
297 - a52dec <unfixed> (embed)
298 - xine-lib <unfixed> (embed)
299
300 libmpeg2
301 - mpeg2dec <unfixed> (embed)
302 - xine-lib <unfixed> (embed)
303
304 libntlm
305 - wget <unfixed> (fork; bug #550436)
306 - curl <unfixed> (fork; bug #550437)
307 - cntlm <unfixed> (fork; bug #550438)
308
309 uw-imap
310 - pine <unfixed> (embed)
311 - alpine <unfixed> (embed)
312
313 imagemagick
314 - graphicsmagick <unfixed> (fork)
315
316 python-urlgrabber
317 - mercurial <unfixed> (embed; bug #531062)
318 - w3af <unfixed> (embed; bug #555372)
319 [experimental] - harvestman <unfixed> (embed; bug #555373)
320
321 beautifulsoup
322 - python-mechanize <unfixed> (embed; bug #555349)
323 - zope2.11 <unfixed> (embed; bug #555350)
324 - twill <unknown> (embed)
325
326 halibut
327 - nsis <unfixed> (fork)
328
329 libghttp
330 - hotway <unfixed> (embed)
331
332 libsndfile
333 - ardour 1:2.7.1-1 (embed)
334
335 glibmm2.4
336 - ardour 1:2.7.1-1 (embed)
337
338 libgnomecanvasmm2.6
339 - ardour 1:2.7.1-1 (embed)
340
341 libsigc++-2.0
342 - ardour 1:2.7.1-1 (embed)
343
344 soundtouch
345 - ardour 1:2.7.1-1 (embed)
346
347 libmms
348 - xine-lib <unfixed> (embed)
349 - mimms <unfixed> (embed)
350
351 fckeditor
352 - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
353 - moin 1.8.2-2 (embed; bug #452599)
354 - karrigell <removed> (embed; bug #452598)
355 - gforge 4.6.99+svn6225-1 (embed)
356 - request-tracker3.8 <unfixed> (embed)
357 - otrs2 <unfixed> (embed)
358
359 ipatlas (not packaged in Debian)
360 - moodle <unfixed> (embed; bug #507185)
361
362 libphp-phpmailer
363 - moodle <unfixed> (embed; bug #507185)
364 - mahara <unfixed> (embed)
365 - symfony <unfixed> (embed)
366 [etch] - phpgroupware <unfixed> (embed)
367 NOTE: phpgroupware-felamimail is only in etch
368 - egroupware <unfixed> (embed; bug #504283)
369 - glpi <unfixed>
370
371 htmlArea (not packaged in Debian)
372 - moodle <unfixed> (embed)
373
374 giflib
375 - wine <unfixed> (embed; bug #466181)
376
377 bennu (not packaged in Debian, http://bennu.sourceforge.net)
378 - moodle <unfixed> (embed)
379
380 smarty
381 - moodle 1.8.2-2 (embed; bug #471158)
382 - gallery2 2.2.5-2 (embed; bug #471160)
383 - mahara 0.9.2-2 (embed; bug #471201)
384 - gosa 2.4beta1-1 (embed; bug #471200)
385
386 TinyMCE
387 - wordpress 2.5.1-3 (embed; bug #478257)
388 - moodle <unfixed> (embed; bug #507185)
389 - knowledgeroot <unfixed> (embed)
390 - joomla <itp> (bug #326398)
391
392 scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
393 - scite <unfixed> (embed)
394 - qscintilla <unfixed> (embed)
395 - qscintilla2 <unfixed> (embed)
396 - geany <unfixed> (fork)
397 - anjuta <unfixed> (embed)
398
399 libphp-adodb
400 - moodle <unfixed> (embed; bug #507185)
401 NOTE: also AdoDB-XML Schema
402 - gallery2 <unfixed> (embed)
403 - phppgadmin <unfixed> (embed)
404 - egroupware <unfixed> (embed)
405 - phpwiki <unfixed> (embed)
406 - torrentflux 2.0beta1-2 (embed)
407 - ipplan <unfixed> (embed)
408 - typo3-src <unfixed> (embed)
409 - cacti <unknown> (embed)
410 [sarge] - cacti <unfixed> (embed)
411 NOTE: dependency exists, but internal version is used
412 - gforge 4.7~rc2-6 (embed)
413 - mahara <unfixed> (embed)
414
415 gzip
416 - linux-kernel <unfixed> (embed)
417 NOTE: lib/inflate.c
418 - klibc <unfixed> (embed)
419 NOTE: based on linux-kernel gzip code
420 - busybox <unfixed> (embed)
421
422 neon
423 - cadaver 0.22.3+debian-1 (embed; bug #188381)
424 - gnome-vfs2 <unfixed> (embed; bug #395874)
425 [etch] - litmus <unfixed> (embed; #395875)
426 - litmus <removed> (embed; #395875)
427 [sarge] - screem <unfixed> (embed)
428 - sitecopy 1:0.16.0-1 (embed; bug #395876)
429 [etch] - tla <unfixed> (embed; bug #395877)
430 [sarge] - tla <unfixed> (embed; bug #395877)
431
432 libmodplug
433 - gst-plugins-bad0.10 <unfixed> (embed)
434
435 libvncserver
436 - vino <unfixed> (embed)
437
438 putty
439 - filezilla <unfixed> (embed)
440
441 tinyxml (not packaged in Debian; itp bug #531968)
442 - filezilla <unfixed>
443 - crystalspace <unfixed> (embed)
444 - libwfut <unfixed> (embed)
445 - rarian <unfixed> (embed)
446 - bulletml <unfixed> (embed)
447 - pokerth <unfixed> (embed)
448 - qutecom <unfixed> (embed)
449 - sofa-framework <unfixed> (embed)
450 - yate <unfixed> (embed)
451 - antigrav <unfixed> (embed)
452 - balder2d <unfixed> (embed)
453 - cal3d <unfixed> (embed)
454 - criticalmass <unfixed> (embed)
455 - ember <unfixed> (embed)
456 - epiphany <unfixed> (embed)
457 - gambit <unfixed> (embed)
458 - noiz2sa <unfixed> (embed)
459 - ogre <unfixed> (embed)
460 - opencity <unfixed> (embed)
461 - openmovieeditor <unfixed> (embed)
462 - pouetchess <unfixed> (embed)
463 - tecnoballz <unfixed> (embed)
464 - trigger-rally <unfixed> (embed)
465 - xmoto <unfixed> (embed)
466 - mapnik <unknown> (embed)
467 NOTE: uses a different XML parser by default
468 - rrootage 0.23a-6 <embed>
469 NOTE: links to libbulltetml
470 - boson <unknown> (embed)
471 NOTE: the embedded code is unused
472
473 gv
474 - evince <unfixed> (embed)
475 NOTE: ps/ tree from gv 3.5.8
476 NOTE: evince-gtk is affected (a component of evince source package)
477
478 libXbae
479 - paw <removed> (embed)
480 [etch] - paw <unfixed> (embed)
481
482 libgtkhtml
483 - claws-mail-extra-plugins <unfixed> (fork)
484
485 libXaw
486 - paw <removed> (embed)
487 [etch] - paw <unfixed> (embed)
488 NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
489
490 libgd2
491 - graphviz <unfixed> (embed)
492 NOTE: lib/gd seems to be 2.0.33
493 - wml <unfixed> (embed)
494 - libwmf <unfixed> (embed)
495 NOTE: derived from gd 1.6.3
496
497 rar
498 - unrar-nonfree <unfixed> (embed)
499
500 unrar-free (maybe this code is derived from the original rar, too?)
501 - clamav <unfixed> (embed)
502 NOTE: seems to be disabled in default config
503
504 mplayer (DirectMedia Object loader)
505 - xine-lib <unfixed> (embed)
506 NOTE: src/libw32dll/
507 - vlc <unfixed> (embed)
508 NOTE: modules/codec/dmo/
509 - mplayer 1.0~rc2-20 (embed)
510
511 libwpd (WordPerfect converter)
512 - openoffice.org <unfixed> (embed)
513
514 fsplib (http://sourceforge.net/projects/fsp/)
515 - gftp <unfixed> (embed)
516 NOTE: lib/fsplib version 0.3
517
518 sprng
519 - tree-puzzle <unfixed> (embed)
520
521 librpcsecgss
522 - krb5 <unfixed> (embed)
523
524 jasper
525 - ghostscript 8.64~dfsg-2 (embed)
526
527 libiris
528 - psi <unfixed> (embed)
529 - kdenetwork <unfixed> (embed)
530 NOTE: kopete embeds libiris but links dynamically to libidn
531 - kdegames <unfixed> (embed)
532 NOTE: ksirk/kde4
533
534 libidn
535 - monotone 0.43-1 (embed)
536 - psi <unfixed> (embed)
537 NOTE: psi embeds libiris which embeds libidn
538 - kdegames <unfixed> (embed)
539 NOTE: kdegames/kde4 embeds libiris which embeds libidn
540
541 lua5.1
542 - monotone 0.43-1 (embed)
543 - nmap 5.00-1 (embed; bug #527997)
544 [lenny] - nmap <unfixed> (embed; bug #527997)
545 - ocropus <unfixed> (embed)
546 - enigma <unfixed> (embed)
547 NOTE: requires lua built with C++
548 - freeciv <unfixed> (embed)
549 - spring <unfixed> (embed)
550
551 libbotan
552 - monotone 0.43-1 (embed)
553
554 NetXX
555 - monotone 0.43-1 (embed)
556
557 libgc
558 - mono <unfixed> (embed)
559
560 lzma
561 - p7zip <unfixed> (embed)
562 - xz-utils <unfixed> (fork)
563
564 lzo
565 - grub2 <unfixed> (embed)
566
567 yassl
568 - mysql-dfsg-5.0 <unfixed> (embed)
569
570 pax code
571 - tar <unfixed> (embed)
572 - cpio <unfixed> (embed)
573
574 t1lib
575 - tetex-bin 2.0.2-1 (embed)
576 - texlive-bin <unknown> (embed)
577
578 guichan
579 - boswars <unfixed> (embed)
580 NOTE: maintainer notified us, working on it
581
582 tolua
583 - boswars <unfixed> (embed)
584 NOTE: maintainer notified us, working on it
585 NOTE: actually tolua++
586 - ocropus <unfixed> (embed)
587 NOTE: actually tolua++
588 - freeciv <unfixed> (embed)
589 NOTE: actually tolua++
590 - enigma <unfixed> (embed)
591
592 asio-dev
593 - luxrender <removed> (embed)
594
595 xine-lib
596 - vlc <unfixed> (embed)
597 NOTE: only parts included in modules/access/rtsp
598
599 netpbm
600 - tcl8.3 <unfixed> (embed)
601 - tcl8.4 <unfixed> (embed)
602 - tcl8.5 <unfixed> (embed)
603 NOTE: generic/tkImgGIF.c
604
605 tk8.5
606 - tk8.0 <removed> (old-version)
607 - tk8.3 <unfixed> (old-version)
608 - tk8.4 <unfixed> (old-version)
609 - perl-tk <unfixable> (fork)
610
611 samba
612 - mc 2:4.6.2~git20080311-1 (embed)
613 NOTE: maintainer is aware of this, currently searching a solution
614
615 plib1.8.4c2
616 - boson <unfixed> (fork)
617 NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
618
619 fribidi
620 - quesoglc <unfixed> (embed)
621 NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
622
623 glew
624 - quesoglc <unfixed> (embed; bug #489341)
625 NOTE: waiting on GLEW_MX version of glew (see bug #474488)
626 - trigger <unfixed> (embed)
627 NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
628 - trigger-rally <unfixed> (embed)
629 NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
630
631 minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
632 - transcend <unfixed> (embed)
633 - cultivation <unfixed> (embed)
634 - passage <unfixed> (embed)
635 - gravitation <unfixed> (embed)
636
637 tar
638 - libarchive <unfixed> (embed)
639 NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
640
641 cpio
642 - libarchive <unfixed> (embed)
643 NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
644
645 webkit
646 - qt4-x11 <unfixed> (embed; bug #479851)
647 [etch] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
648 [lenny] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
649 - kdelibs <unfixed> (old-version)
650 - kde4libs <unfixed> (fork)
651
652 ftgl
653 - blender 2.46+dfsg-1 (embed)
654
655 wv
656 - abiword <unfixed>
657
658 qemu
659 - kvm <unfixed> (embed; bug #543159)
660 NOTE: the kvm package will be removed from sid and squeeze soon (after
661 NOTE: which it will only be in experimental). superceded by qemu-kvm.
662 - qemu-kvm <unfixed> (embed; bug #560853)
663 - xen-3 3.4.2-2 (embed; bug #560856)
664 - xen-unstable <unfixed> (embed; bug #560856)
665
666 vgabios
667 - kvm <unfixed> (embed; bug #489442)
668
669 bochs
670 - kvm <unfixed> (embed; bug #489442)
671
672 speex
673 - vorbis-tools <unfixed> (embed)
674 NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
675 - gst-plugins-good0.10 <unfixed> (embed)
676 - xine-lib <unfixed> (embed)
677 - libfishsound <unfixed> (embed)
678 - libannodex <removed> (embed)
679 - vlc <unfixed> (embed)
680 - xmms-speex <unfixed> (embed)
681 - libsdl-sound1.2 <unfixed> (embed)
682 - sweep <unfixed> (embed)
683
684 libreadline
685 - magic <itp> (old-version)
686
687 opcode
688 - ode <unfixed> (embed)
689 NOTE: opcode is not a package in debian, it is just embedded
690 NOTE: http://www.codercorner.com/Opcode.htm
691
692 gimpact
693 - ode <unfixed> (embed)
694 NOTE: gimpact is not a package in debian, it is just embedded
695 NOTE: http://gimpact.sf.net
696
697 mochikit
698 - mahara <unfixed> (embed)
699 NOTE: they require extra patches, still unmerged upstream
700 - ntop <unfixed> (embed)
701 - coherence 0.6.2-1 (embed)
702 - paste <unfixed> (embed)
703 - turbogears <unfixed> (embed)
704 - plone3 <unfixed> (embed)
705 - xulrunner <unfixed> (embed)
706 - libjifty-plugin-chart-perl <unfixed> (embed)
707 - sabnzbdplus <unfixed> (embed)
708 - tgmochikit <unfixed> (embed)
709
710 prototypejs
711 - netbeans-ide 6.0.1+dfsg-2 (embed)
712 - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
713 - webcit <unfixed> (embed; bug #555219)
714 - asterisk 1:1.6.2.0~rc3-1 (embed)
715 - libjson-ruby 1.1.4-1 (embed; bug #555224)
716 - lucene2 2.9.1+ds1-2 (embed; bug #555226)
717 - horde3 <unfixed> (embed)
718 - knowledgeroot <unfixed> (embed; bug #555230)
719 - mediatomb <unfixed> (embed; bug #555233)
720 - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
721 - ebug-http <removed> (embed; bug #555236)
722 - libaws 2.7-1 (embed; bug #555222)
723 - phpgedview <removed> (embed)
724 - poker-network <removed> (embed; bug #555238)
725 - rails 2.1.0-6 (embed)
726 - wordpress 2.5.0-2 (embed; bug #555243)
727 - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
728 TODO: search through all of the other zope packages
729 - ampache 3.4.1-2 (embed)
730 - exaile 0.2.14+debian-2.1 (embed; bug #555245)
731 - hobix 0.5~svn20070319-4 (embed; bug #555247)
732 - zabbix 1.6.6-4 (embed; bug #555250)
733 - chora2 <unfixed> (embed; bug #555253)
734 - gollem <unfixed> (embed; bug # 555254)
735 - jscropperui 1.2.1-1 (embed; bug #555257)
736 - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
737 - ingo1 <unfixed> (embed; bug #555261)
738 - kronolith2 <unfixed> (embed; bug #555262)
739 - activeldap <unfixed> (embed)
740 - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
741 - mantis <unfixed> (embed; bug #555265)
742 - otrs2 2.3.4-6 (embed; bug #555267)
743 - webcalendar <unfixed> (embed; bug #555269)
744 - redmine 0.9.0~svn2907-1 (embed; bug #555270)
745 - jifty 0.90519-1 (embed; bug #555271)
746 - jquery <unfixed> (embed; bug #555272)
747 - passenger 2.2.5debian1-1 (embed; bug #555273)
748 - plone3 <unfixed> (embed; bug #555275)
749 - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
750 - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
751 - xulrunner <unfixed> (embed)
752 NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
753
754 gdb
755 - insight <unfixed> (embed)
756
757 e2fsprogs
758 - ldiskfsprogs <unfixable> (fork)
759
760 quazip (not packaged in Debian)
761 - qcake <unfixed> (embed)
762 NOTE: starting with upstream version 0.6.4
763
764 exo
765 - pcmanfm <unfixed> (embed; bug #499677)
766 NOTE: slightly modified source code
767
768 java
769 - openjdk-6 <unfixed>
770 - sun-java5 <unfixed>
771 - sun-java6 <unfixed>
772
773 libphp-snoopy
774 - ampache 3.4.1-2 (embed; bug #504169)
775 - gforge 4.6.99+svn6094-2 (embed)
776 - mahara 1.0.5-2 (embed; bug #504170)
777 - pixelpost 1.7.1-5 (embed; bug #504171)
778 - mediamate 0.9.3.6-5 (embed; bug #504172)
779 - opendb <removed> (embed; bug #504173)
780 [etch] - opendb <unfixed> (embed; bug #504173)
781 - wordpress 2.5.1-9 (embed; bug #443948)
782 - moodle <unfixed> (embed; bug #507185)
783 [etch] - phpgroupware <unfixed> (embed)
784 NOTE: phpgroupware-felamimail
785 - magpierss 0.72-3 (embed; bug #431089)
786
787 jquery
788 - zekr <unfixed> (embed)
789 - wordpress <unknown> (embed)
790 - yocto-reader <unfixed> (embed)
791 - textpattern <unfixed> (embed)
792 - genshi 0.5.1-1 (embed)
793 NOTE: compressed file under examples/ dir
794 - prewikka <unfixed> (embed)
795 - libramaze-ruby <unfixed> (embed)
796 - drupal5 <unfixed> (embed)
797 - b2evolution <unfixed> (embed)
798 - wesnoth <unfixed> (embed)
799
800 tablesorter (jquery plugin, not packaged yet)
801 - wesnoth <unfixed> (embed)
802
803 kses
804 - wordpress <unfixed> (embed; bug #504242)
805 NOTE: their copy has all methods renamed to wp_<foo>
806 NOTE: kses isn't in Debian, RFP: #504240
807 - moodle <unfixed> (embed; bug #507185)
808 - egroupware <unfixed> (embed)
809
810 magpierss
811 - wordpress <unfixed> (embed; bug #504242)
812 - moodle <unfixed>
813
814 php-gettext
815 - wordpress 2.8.4-1 (embed; bug #504242)
816 - docbookwiki <unfixed> (embed)
817 NOTE: non-free
818
819 libphp-ixr (name may change, it is the Incutio XML-RPC)
820 - wordpress <unfixed> (embed; bug #504242)
821 NOTE: libphp-ixr isn't in Debian, RFP: #504236
822 - dokuwiki <unfixed> (embed)
823 - textpattern <unfixed> (embed)
824
825 libphp-cas
826 - glpi <unfixed> (embed)
827 - moodle <unfixed> (embed; bug #505984)
828
829 scriptaculous (prototype.js is among the embeds in the following)
830 - glpi <unfixed> (embed)
831 - libaws <unfixed> (embed; bug #555222)
832 - op-panel <unfixed> (embed)
833 - symfony <unfixed> (embed)
834 NOTE: maintainer says there are extra incompatible changes required
835 - pixelpost 1.7.1-6 (embed)
836 - webhelpers <unfixed> (embed)
837 - qwik <removed> (embed; bug #555241)
838 - smokeping <unfixed> (embed)
839 - turba2 <unfixed> (embed)
840 - typo3-src 4.2.3-1 (embed)
841 - request-tracker3.6 <unfixed> (embed)
842 - request-tracker3.8 <unfixed> (embed)
843 - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
844 - wordpress 2.5.0-2 (embed)
845 - libhtml-prototype-perl 1.48-3 (embed)
846
847 libmarkdown-php
848 - moodle <unfixed> (embed; bug #507185)
849 - pixelpost 1.7.1-6 (embed)
850
851 php-openid
852 - wordpress-openid <itp> (embed)
853
854 geshi
855 - dokuwiki 0.0.20080505-3.1 (embed)
856 - pgfouine 1.0-1.1 (embed)
857 - websvn 2.1.0-1 (embed)
858
859 webcalendar
860 - gforge 4.7~rc2-6 (embed; bug #504758)
861
862 libical
863 - kdepim <unfixed> (fork)
864 - kdepimlibs <unfixed> (fork)
865 NOTE: fixed in KDE4 post 4.1.x series
866 - claws-mail-extra-plugins <unfixed> (fork)
867
868 libltdl3
869 - kdelibs <unfixed> (embed)
870 NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
871 - synfig <unfixed> (embed)
872
873 harfbuzz
874 - qt4-x11 <unfixed> (embed)
875
876 libzip
877 - php5 <unfixable> (modified-embed)
878 - odt2txt <unfixed> (embed; bug #523808)
879
880 json.php (not packaged; should be replaced with php's built-in functions)
881 - moodle <unfixed>
882 - yui <unfixed>
883 - gallery2 <unfixed>
884 - dokuwiki <unfixed>
885 - typo3-src <unfixed>
886
887 php-fpdf
888 - tcpdf <itp> (fork)
889 - moodle <unfixed>
890 - phpwiki <unfixed>
891 - egroupware <unfixed>
892 - ldap-account-manager <unfixed> (fork)
893
894 tcpdf (itp: #495985)
895 - moodle <unfixed>
896 - phpmyadmin <unfixed>
897
898 typo3
899 - moodle <unfixed>
900
901 spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
902 - moodle <unfixed>
903 - gosa <unfixed>
904
905 php-ole (itp: #487558)
906 - moodle <unfixed>
907
908 pieforms (http://www.catalyst.net.nz)
909 - mahara <unfixed>
910
911 savant2 (http://phpsavant.com)
912 - egroupware <unfixed>
913
914 rssparser (http://nwow.org)
915 - egroupware <unfixed>
916 - phpgroupware <unfixed>
917
918 lcms
919 - openjdk-6 <unfixed> (fork)
920
921 libphp-phplayersmenu
922 - diogenes <unfixed>
923 - phpldapadmin <unfixed>
924
925 libphp-pclzip
926 - docvert <unfixed>
927 - moodle <unfixed>
928 - egroupware <unfixed>
929
930 libphp-simplepie
931 - dokuwiki <unfixed>
932 - wordpress <unfixed>
933
934 libphp-jpgraph
935 - egroupware <unfixed>
936
937 php-simpletest
938 - moodle <unfixed>
939
940 libpng
941 - iceweasel <not-affected> (uses xulrunner)
942 - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
943 - iceape 1.0.13~pre080614i-0etch1 (embed)
944 - xulrunner 1.9.0.13-1 (embed)
945 [lenny] - xulrunner 1.9.0.11-0lenny1
946 [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
947 - gamera 3.2.3-1 (embed)
948
949 irssi
950 - silc-client <unfixed> (embed)
951 NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
952
953 extc
954 - mtasc <unfixed> (embed)
955 - haxe <unfixed> (embed)
956
957 swflib
958 - mtasc <unfixed> (embed)
959 - haxe <unfixed> (embed)
960
961 libitext-java
962 - bouncycastle 2.1.4-1 (embed)
963
964 python-ply
965 - pyke <unfixed> (embed; bug #555363)
966 - pywbem 0.7.0-4 (embed; bug #555364)
967 - sepolgen <unfixed> (embed; bug #555365)
968 - zope-textindexng3 <unknown> (embed)
969 - iceweasel <not-affected> (uses xulrunner)
970 - xulrunner <unknown> (embed)
971 - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
972
973 libdumbnet (libdnet upstream)
974 - nmap <unfixed> (fork)
975
976 gcc-4.4
977 - gcc-mingw32 <unfixed> (embed)
978
979 camlimages
980 - advi <unfixed> (static; bug #550441)
981
982 memcached
983 - memcachedb <unfixed> (embed)
984
985 yajl
986 - argyll <unfixed> (embed; bug #544223)
987 NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
988
989 nusoap
990 - gforge 4.8.2-1 (embed)
991 - ampache <unfixed> (embed)
992 - poker-web <unfixed> (old-version)
993 - moodle <unfixed> (old-version)
994 NOTE: code is not used when running under php5 and soap is enabled
995 - phpwiki <unfixed> (old-version)
996 - gallery2 <unfixed> (old-version)
997 - typo3-src <unfixed> (old-version)
998
999 libept
1000 - adept <unfixed> (embed; bug #540649)
1001
1002 libvorbis
1003 - iceweasel <not-affected> (uses xulrunner)
1004 - xulrunner <unfixed> (embed; bug #540959)
1005 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1006 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1007 - iceape <unfixed> (embed)
1008 [etch] - iceape <not-affected> (introduced in 2.0)
1009 [lenny] - iceape <not-affected> (introduced in 2.0)
1010
1011 cairo
1012 - iceweasel <not-affected> (uses xulrunner)
1013 - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1014
1015 liboggz
1016 - iceweasel <not-affected> (uses xulrunner)
1017 - xulrunner <unfixed> (embed; bug #540959)
1018 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1019 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1020 - iceape <unfixed> (embed)
1021 [etch] - iceape <not-affected> (introduced in 2.0)
1022 [lenny] - iceape <not-affected> (introduced in 2.0)
1023
1024 liboggplay
1025 - iceweasel <not-affected> (uses xulrunner)
1026 - xulrunner <unfixed> (embed; bug #540959)
1027 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1028 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1029 - iceape <unfixed> (embed)
1030 [etch] - iceape <not-affected> (introduced in 2.0)
1031 [lenny] - iceape <not-affected> (introduced in 2.0)
1032
1033 php-net-dnsbl
1034 - serendipity <unfixed> (embed; bug #541740)
1035
1036 php-onyx-rss
1037 - serendipity <unfixed> (embed; bug #541740)
1038
1039 php-text-wiki
1040 - serendipity <unfixed> (embed; bug #541740)
1041
1042 php-xml-rpc
1043 - serendipity <unfixed> (embed; bug #541740)
1044
1045 polarssl (does not have a shared library)
1046 - pdkim <itp> (embed; bug #543150)
1047 - xyssl <unfixed> (old-version)
1048
1049 pidgin
1050 - gaim <removed> (old-version)
1051 - qutecom <unfixed> (embed; bug #559785)
1052
1053 icu
1054 - webkit 1.0.1-1 (embed; bug #547214)
1055 - texlive-bin <unfixed> (fork)
1056 NOTE: texlive upstream working with icu upstream to merge their changes
1057
1058 cyrus-imapd-2.2
1059 - kolab-cyrus-imapd <unfixed> (fork)
1060 - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1061
1062 python-cxx-dev
1063 - freecad 0.9.2646.3-1 (embed; bug #547936)
1064
1065 zipios++
1066 - freecad 0.9.2646.3-1 (embed; bug #547941)
1067 - enigma 0.92.3-3 (embed)
1068 NOTE: likely fixed earlier, marking etch's version as fixed
1069
1070 linux-2.6
1071 - kvm <removed> (embed; bug #549973) [./kernel/*]
1072 - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1073 - kernel-source-2.6.8 <removed> (old-version)
1074 - kernel-source-2.4.27 <removed> (old-version)
1075 - kernel-source-2.4.24 <removed> (old-version)
1076 - kernel-source-2.2.25 <removed> (old-version)
1077 - kernel-source-2.2.20 <removed> (old-version)
1078
1079 libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1080 - kvm <removed> (embed) [./libfdt/*]
1081 - qemu-kvm <unfixed> (embed) [./libfdt/*]
1082
1083 qweb (not packaged)
1084 - ajaxterm <unfixed>
1085
1086 opensaml2
1087 - opensaml <removed> (old-version)
1088
1089 shibboleth-sp2
1090 - shibboleth-sp <removed> (old-version)
1091
1092 tuxonice-userui
1093 - suspend2-userui <removed> (old-version)
1094
1095 expat
1096 - w3c-libwww <removed> (embed; bug #551941)
1097 [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1098 - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1099 - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1100 - python2.4 <unfixable> (embed; bug #553403)
1101 - python-4suite <unfixed> (embed; bug #516935)
1102 - wxwindows2.4 <removed> (embed)
1103 - wxwidgets2.6 2.6.3.2.2-4 (embed)
1104 - wxwidgets2.8 2.8.10.1-2 (embed)
1105 - celementtree 1.0.5-8 (embed)
1106 NOTE: Maybe that was fixed even earlier
1107 - audacity 1.3.2-1 (embed)
1108 - matanza <unfixed> (embed)
1109 - tdom 0.8.3~20080525-1 (embed)
1110 - udunits 2.1.8-4 (embed)
1111 - apr-util 1.2 (embed)
1112 - ayttm <unfxed> (embed; bug #561006)
1113 - cableswig <unfixed> (embed)
1114 - cadaver <unfixed> (embed)
1115 - cmake 2.6.0-6 (embed)
1116 - coin3 <unfixed> (embed)
1117 - gdcm 2.0.14-2 (embed)
1118 - ghostscript <unfixed> (embed)
1119 - grmonitor <removed> (embed)
1120 - iceape <unfixed> (embed)
1121 - insighttoolkit 3.16.0-1 (embed)
1122 NOTE: insighttoolkit might've been fixed earlier
1123 - libparagui1.1 1.0.2-1 (embed)
1124 - paraview <unfixed> (embed)
1125 - poco <unfixed> (embed)
1126 - simgear <unfixed> (embed)
1127 - sitecopy 1:0.16.0-1
1128 - smart 1.0-1 (embed)
1129 - swish-e <unfixed> (embed)
1130 - tla <unfixed> (embed)
1131 - vtk 4.1.20030227-1 (embed)
1132 - wbxml2 <unfixed> (embed)
1133 - xmlrpc-c <unfixed> (embed)
1134 - iceweasel <unfixed> (embed)
1135 - kompozer <unfixed> (embed)
1136 - vxl 1.13.0-2 (embed)
1137 - xulrunner <unfixed> (embed)
1138 - apache2 2.2 (embed)
1139 - texlive-bin <not-affected> (Embedded code not compiled in)
1140 - vnc4 <unfixed> (embed)
1141 - xotcl <unfixed> (embed)
1142
1143 xerces-c
1144 - xerces-c2 <unfixed> (old-version)
1145 - xerces27 <removed> (old-version)
1146
1147 md5 (RSA's version; not the gnu version provided by coreutils)
1148 - w3c-libwww <removed> (embed; bug #551942)
1149 [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1150
1151 enet
1152 - sauerbraten <unfixed> (embed; #497194)
1153
1154 eglibc
1155 - glibc <removed> (old-version)
1156
1157 galib
1158 - gamera 3.2.3-1 (embed)
1159
1160 configobj
1161 - bzr <unfixed> (embed; bug #555336)
1162 - elisa <unfixed> (embed; bug #555337)
1163 - gaupol <unfixed> (embed; bug #555338)
1164 - ipython <unfixed> (embed; bug #555339)
1165 - pida <unfixed> (embed; bug #555340)
1166 - psychopy <unfixed> (embed; bug #555341)
1167 - rest2web <unfixed> (embed; bug #555342)
1168 - auth2db <unknown> (embed)
1169 - dynagen <unknown> (embed)
1170 - iceweasel <unknown> (embed)
1171 - sabnzbdplus <unknown> (embed)
1172 - xulrunner <unknown> (embed)
1173 - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1174
1175 python-clientform
1176 - bibus <unfixed> (embed; bug #555332)
1177 - zope2.10 <unfixed> (embed; bug #555333)
1178 - zope2.11 <unfixed> (embed; bug #555334)
1179 - python-mechanize <unknown> (embed)
1180 - twill <unknown> (embed)
1181
1182 python-mechanize
1183 - zope2.10 <unfixed> (embed; bug #555337)
1184 - zope2.11 <unfixed> (embed; bug #555338)
1185 - twill <unknown> (embed; bug #555339)
1186
1187 pexpect
1188 - duplicity 0.6.06-1 (embed; bug #555361)
1189 - hplip <unfixed> (embed; bug #555362)
1190 - smart <unfixed> (embed; bug #555363)
1191
1192 pyparsing
1193 - bauble <unfixed> (embed; bug #555366)
1194 - boa-constructor 0.6.1-8 (embed; bug #555367)
1195 - calibre <unfixed> (embed; bug #555368)
1196 - matplotlib <unfixed> (embed; bug #531024)
1197 - zhpy <unfixed> (embed; bug #555370)
1198 - polybori <unknown> (embed)
1199 - python-whoosh <unknown> (embed)
1200 - twill <unknown> (embed)
1201 - zope-textindexng3 <unknown> (embed)
1202
1203 python-pysqlite2
1204 - python2.4 <unfixed> (embed; bug #553403)
1205 - python2.5 <unfixed> (embed; bug #553403)
1206
1207 celementtree
1208 - python2.5 <unfixed> (embed)
1209 - smart 1.0-1 (embed)
1210 [etch] - smart <unfixed> (embed)
1211
1212 elementtree
1213 - python2.5 <unfixed> (embed)
1214 - bzr <unfixed> (embed; bug #555343)
1215 - gedit 2.28.2-1 (embed; bug #555344)
1216 - smart 1.0-1 (embed)
1217 [etch] - smart <unfixed> (embed)
1218 - solfege <unfixed> (embed; bug #555345)
1219 - w3af <unfixed> (embed; bug #555346)
1220 - python-qt4 <unknown> (embed)
1221 - sphinx <unknown> (embed)
1222 - python-nltk <itp> (embed)
1223
1224 python2.5
1225 - python2.4 <unfixed> (old-version)
1226 - jython <unfixed> (embed)
1227 NOTE: embeds many stdlib modules
1228 - python-django <unfixed> (embed; bug #555419)
1229 NOTE: embeds stdlib modules: doctest, decimal
1230 - gamera 3.2.3-1 (embed)
1231 NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1232 - boa-constructor <unfixed> (embed; bug #555426)
1233 NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1234 - nicotine <unfixed> (embed; bug #555427)
1235 NOTE: embeds stdlib modules: ConfigParser
1236 - museek+ <unfixed> (embed; bug #555428)
1237 NOTE: embeds stdlib modules: ConfigParser
1238 - vegastrike-data <unfixed> (embed)
1239 NOTE: embeds many stdlib modules
1240 - codespeak-lib 1.1.1-1 (embed; bug #555420)
1241 NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1242 - config-manager <unfixed> (embed; bug #555423)
1243 NOTE: embeds stdlib modules: optparse
1244 - jhbuild 2.28.0-1 (embed; bug #555421)
1245 NOTE: embeds stdlib modules: optparse, subprocess
1246 - smart <unfixed> (embed; bug #555432)
1247 NOTE: embeds stdlib modules: optparse
1248 - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1249 NOTE: embeds stdlib modules: doctest
1250 - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1251 NOTE: embeds stdlib modules: doctest
1252 - distribute <unfixed> (embed)
1253 NOTE: embeds stdlib modules: doctest
1254 - python-setuptools <unfixed> (embed; bug #555435)
1255 NOTE: embeds stdlib modules: doctest
1256 - zope.testing <unfixed> (embed; bug #555436)
1257 NOTE: embeds stdlib modules: doctest
1258 - translate-toolkit <unfixed> (embed; bug #555422)
1259 NOTE: embeds stdlib modules: textwrap, contextlib
1260 - libtpclient-py <unfixed> (embed; bug #555424)
1261 NOTE: embeds stdlib modules: subprocess
1262 - grass <unfixed> (embed; bug #555425)
1263 NOTE: embeds stdlib modules: subprocess
1264 - coherence <unfixed> (embed; bug #555429)
1265 NOTE: embeds stdlib modules: uuid
1266 - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1267 NOTE: embeds stdlib modules: uuid
1268 - setroubleshoot <unfixed> (embed; bug #555431)
1269 NOTE: embeds stdlib modules: uuid
1270 - linkchecker <unfixed> (embed; bug #555414)
1271 NOTE: embeds msgfmt.py script
1272 - imdbpy <unfixed> (embed)
1273 NOTE: embeds msgfmt.py script
1274 - kiwi <unfixed> (embed)
1275 NOTE: embeds msgfmt.py script
1276 - moin <unfixed> (embed)
1277 NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1278 - plone3 <unfixed> (embed)
1279 NOTE: embeds msgfmt.py script
1280 - roundup <unfixed> (embed)
1281 NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1282 - rednotebook <unfixed> (embed; bug #555415)
1283 NOTE: embeds msgfmt.py script
1284 - turbogears <unfixed> (embed)
1285 NOTE: embeds msgfmt.py script
1286 - elisa <unfixed> (embed)
1287 NOTE: embeds msgfmt.py script, stdlib modules: uuid
1288 - calibre <unfixed> (embed)
1289 NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1290 - mailman <unfixed> (embed; #555416)
1291 NOTE: embeds msgfmt.py script
1292 - python-docutils <unknown> (embed)
1293 NOTE: embeds stdlib modules: optparse, textwrap
1294 - python-imaging <unknown> (embed)
1295 NOTE: embeds stdlib modules: doctest
1296 - python-mechanize <unknown> (embed)
1297 NOTE: embeds stdlib modules: doctest
1298 - twill <unknown> (embed)
1299 NOTE: embeds stdlib modules: subprocess
1300 - zeroc-ice <unknown> (embed)
1301 NOTE: embeds stdlib modules: subprocess
1302 - wxwidgets2.8 <unknown> (embed)
1303 NOTE: embeds stdlib modules: subprocess
1304 - cycle <unknown> (embed)
1305 NOTE: embeds msgfmt.py script
1306 - deluge <unknown> (embed)
1307 NOTE: embeds msgfmt.py script
1308 - opendict <unknown> (embed)
1309 NOTE: embeds msgfmt.py script
1310 - openerp-client <unknown> (embed)
1311 NOTE: embeds msgfmt.py script
1312 - rapidsvn <unknown> (embed)
1313 NOTE: embeds msgfmt.py script
1314 - wammu <unknown> (embed)
1315 NOTE: embeds msgfmt.py script
1316 - gaphor <unknown> (embed)
1317 NOTE: embeds msgfmt.py script
1318 - pida <unknown> (embed)
1319 NOTE: embeds msgfmt.py script
1320 - python-formencode <unknown> (embed)
1321 NOTE: embeds msgfmt.py script
1322 - duplicity <unfixed> (embed)
1323 NOTE: embeds stdlib module: urlparse, tarfile
1324 - pygopherd <unfixed> (embed)
1325 NOTE: embeds stdlib module: zipfile
1326
1327 argparse
1328 - twill <unfixed> (embed; bug #555347)
1329 - ipython <unfixed> (embed; bug #555348)
1330
1331 coherence
1332 - elisa <unfixed> (embed; bug #555335)
1333
1334 simpletal
1335 - plastex <unfixed> (embed; bug #555371)
1336
1337 flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1338 - postr <unfixed> (embed)
1339 - elisa <unfixed> (embed)
1340
1341 simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1342 - apertium-tolk <unfixed> (embed)
1343 - ipython <unfixed> (embed)
1344 - virtaal <unfixed> (embed)
1345
1346 distribute
1347 - setuptools <removed> (old-version)
1348
1349 rails
1350 - jruby1.2 <unfixed> (embed) [./bench/rails/*]
1351 - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1352 - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1353 - thin <unfixed> (embed) [./spec/rails_app/*]
1354 NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1355 NOTE: be dangerous if developers are naively basing their code off of the examples
1356 NOTE: prototype.js is among the example files
1357
1358 lucene2 (prototype.js is among the embeds in the following)
1359 - lucene <unfixed> (old-version)
1360 - pylucene <unfixed> (embed)
1361 - libpdfbox-java <unfixed> (embed)
1362 - libfontbox-java <unfixed> (embed)
1363 - libjempbox-java <unfixed> (embed)
1364 - solr <unfixed> (embed)
1365
1366 unicode-data
1367 - syslinux <unfixed> (embed)
1368 - camomile <unfixed> (embed)
1369 - fribidi <unfixed> (embed)
1370 - m17n-db <unfixed> (embed)
1371 - sbcl <unfixed> (embed)
1372 - heimdal <unfixed> (embed)
1373 - icu <unfixed> (embed)
1374 - icu4j <unfixed> (embed)
1375 - krb5 <unfixed> (embed)
1376 - moodle <unfixed> (embed)
1377 - openldap <unfixed> (embed)
1378 - pike7.6 <unfixed> (embed)
1379 - samba <unfixed> (embed)
1380 - samba4 <unfixed> (embed)
1381 - cmucl <unfixed> (embed)
1382 - typo3-src <unfixed> (embed)
1383 - mauve <unfixed> (embed)
1384 - texlive-bin <unfixed> (embed)
1385 - ypsilon <unfixed> (embed)
1386 - jeuclid <unfixed> (embed)
1387 - charmap.app <unfixed> (embed)
1388 - clisp <unfixed> (embed)
1389 - gnulib <unfixed> (embed)
1390 - opensrs-client <unfixed> (embed)
1391 - saxonb <unfixed> (embed)
1392 - rails <unfixed> (embed)
1393
1394 feedparser
1395 - rawdog <unfixed> (embed; bug #383422)
1396 - miro <unfixed> (embed; bug #555351)
1397 - calibre <unfixed> (embed; bug #555352)
1398 - freevo <unfixed> (embed; bug #555353)
1399 - pida <unfixed> (embed; bug #555354)
1400 - planet-venus <unfixed> (embed; bug #555355)
1401 - plone3 <unfixed> (embed; bug #555356)
1402 - exaile 0.2.14+debian-1 (embed)
1403 - screenlets 0.1.2-3 (embed)
1404 NOTE: included twice
1405
1406 agg:
1407 - matplotlib <unfixed> (embed: bug #377271)
1408 - contextfree <unfixed> (embed)
1409 NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1410 - exactimage <unfixed> (embed)
1411 - python-enable <unfixed> (embed)
1412 - mapnik 0.5.1-3 (embed)
1413 NOTE: links statically to agg, but shared library is not available (bug #377271)
1414
1415 vtk
1416 - paraview <unfixable> (embed; bug #495426)
1417
1418 txt2tags
1419 - rednotebook <unfixed> (embed)
1420
1421 htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1422 - gajim <unfixed> (embed)
1423 - emesene <unfixed> (embed)
1424 - convirt <unfixed> (embed)
1425 - pida <unfixed> (embed)
1426 - rednotebook <unfixed> (embed)
1427
1428 horde3 (prototype.js is among the embeds in the following)
1429 - mnemo2 <unfixed> (embed)
1430 - nag2 <unfixed> (embed)
1431 - wordpress <unfixed> (embed)
1432 NOTE: Text_Diff (wp-includes/Text/Diff*)
1433
1434 cimg
1435 - gmic <itp> (embed)
1436
1437 mootools
1438 - gmic <itp> (embed)
1439
1440 openldap
1441 - openldap2.3 <removed> (old-version)
1442
1443 grub2
1444 - grub <unfixed> (old-version)
1445
1446 gnupginterface
1447 - duplicity <unfixed> (embed)
1448
1449 python-dateutil
1450 - awn-extras-applets <unfixed> (embed)
1451 - matplotlib <unknown> (embed)
1452
1453 cups
1454 - cupsys <removed> (old-version)
1455
1456 yui
1457 - bcfg2 <not-affected> (present in source but not included in any binary files)
1458 - serendipity <unfixed> (embed; bug #557746)
1459 - moodle 1.8.2.dfsg-5 (embed)
1460 - jifty 0.91117-1 (embed; bug #557748)
1461 - webgui 7.7.26-1 (embed)
1462 - loggerhead 1.17-1 (embed)
1463
1464 quake3 (vanilla source not packaged in debian)
1465 - openarena <unfixable> (fork)
1466
1467 quake2 (vanilla source not packaged in debian)
1468 - alien-arena <unfixable> (fork)
1469 - warsow <unfixable> (fork)
1470
1471 libtheora
1472 - iceweasel <not-affected> (uses xulrunner)
1473 - xulrunner <unfixed> (embed; bug #540959)
1474 [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1475 [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1476 - iceape <unfixed> (embed; bug #559276)
1477 [etch] - iceape <not-affected> (introduced in iceape 2.0)
1478 [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1479
1480 dtoa
1481 - bfilter <unfixed> (embed)
1482 - cacao <unfixed> (embed)
1483 - cdrdao <unfixed> (embed)
1484 - classpath <unfixed> (embed)
1485 - freej <unfixed> (embed)
1486 - iceape <unfixed> (embed)
1487 - iceweasel <unfixed> (embed)
1488 - jscoverage <unfixed> (embed)
1489 - kde4libs <unfixed> (embed)
1490 - kdelibs <unfixed> (embed)
1491 - kompozer <unfixed> (embed)
1492 - libv8 <unfixed> (embed)
1493 - mono <unfixed> (embed)
1494 - newlib <unfixed> (embed)
1495 - nspr <unfixed> (embed)
1496 - php5 <unfixed> (embed)
1497 - polyml <unfixed> (embed)
1498 - qt4-x11 <unfixed> (embed)
1499 - rhino <unfixed> (embed)
1500 NOTE: code translated to Java
1501 - ruby1.8 <unfixed> (embed)
1502 - ruby1.9 <unfixed> (embed)
1503 - ruby1.9.1 <unfixed> (embed)
1504 - sdd <unfixed> (embed)
1505 - sfind <unfixed> (embed)
1506 - star <unfixed> (embed)
1507 - tinymux <unfixed> (embed)
1508 - virtualbox-ose <unfixed> (embed)
1509 - webkit <unfixed> (embed)
1510 - xulrunner <unfixed> (embed)
1511
1512 ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1513 - firegpg <unfixed> (embed)
1514 - enigmail <unfixed> (embed)
1515
1516 ptmalloc (not packaged in Debian)
1517 - crystalspace <unfixed> (embed)
1518 - qt4-x11 <unfixed> (embed)
1519
1520 svgalib
1521 - usplash <unfixed> (embed)
1522
1523 bogl
1524 - usplash <unfixed> (embed)
1525
1526 taglist
1527 - usplash <unfixed> (embed)
1528
1529 portaudio
1530 - audacity <unfixed> (embed; bug #323711)
1531
1532 nyquist
1533 - audacity <unfixed> (embed)
1534 NOTE: embeds a forked nyquist with support for a shared library
1535
1536 vamp-plugin-sdk
1537 - audacity <unfixed> (embed)
1538
1539 wordpress
1540 - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1541
1542 php5
1543 - php4 <removed> (old-version)
1544
1545 classpath
1546 - libgnucrypto-java <unfixed> (embed; bug #559788)
1547
1548 libtool
1549 - apr <unfixed> (static; bug #489625)
1550 NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1551 - arts <unfixed> (embed)
1552 - bochs 2.4.2-1 (embed; bug #560884)
1553 - camserv <unfixed> (embed)
1554 - collectd <unfixed> (embed)
1555 - courier-authlib 0.58-4 (embed)
1556 NOTE: The etch version of courier-authlib was the earliest version checked, might be fixed earlier
1557 - cvsnt <unfixed> (embed)
1558 - dico <not-affected> (Uses the system copy of ltdl)
1559 - freeradius 0.1+20010527-1 (embed)
1560 NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1561 - ggobi 2.1.9~20091212-1 (embed)
1562 - glame 2.0.1-4 (embed)
1563 NOTE: The etch version of glame was the earliest version checked, might be fixed earlier
1564 - gnash <unfixed> (embed)
1565 - gnu-smalltalk <unfixed> (embed)
1566 - google-gadgets 0.10.5-0.3 (embed)
1567 NOTE: 0.10.5-0.3 was the earliest version checked, was fixed earlier
1568 - graphicsmagick 1.3.5-6 (embed)
1569 - graphviz 2.8-3 (embed)
1570 NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1571 - guile-1.6 1.6.8-7 (embed)
1572 - hamlib <unfixed> (embed)
1573 - hercules <unfixed> (embed)
1574 - jags 1.0.4-3 (embed; bug #560864)
1575 - kdelibs <unfixed> (embed)
1576 - libannodex <removed> (embed)
1577 - libextractor <unfixed> (embed)
1578 - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1579 - libtunepimp <unfixed> (embed)
1580 - mp4h <unfixed> (embed)
1581 - naim <unfixed> (embed)
1582 - parser-mysql <unfixed> (embed)
1583 - pinball <unfixed> (embed)
1584 - redland <unfixed> (embed)
1585 - siproxd <unfixed> (embed)
1586 - ski <unfixed> (embed)
1587 - synfig <unfixed> (embed)
1588 - unixodbc 2.2.4-5 (embed)
1589 - xmlsec1 <not-affected> (Doesn't enable dynamic loading of crypto modules)
1590 - clamav 0.95+dfsg-1 (embed)
1591 - imagemagick 6:6.2.3.1-1 (embed)
1592 - hypre 2.4.0b-5 (embed)
1593 - lam <unfixed> (embed)
1594 - openmpi <unfixable> (embed; bug #559386)
1595 - parser <unfixed> (embed)
1596 - pdsh 2.18-5 (embed; bug #560892)
1597 - sbnc 1.2-8 (embed)
1598 - sdcc <unfixed> (embed)
1599 - wml <unfixed> (embed)
1600 - proftpd-dfsg <unfixed> (embed; bug #561748)
1601 - babel 1.4.0.dfsg-5 (embed)
1602 - libprelude 0.9.14-2 (embed)
1603 - heartbeat 2.1.4-7 (embed)
1604 NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1605 NOTE: might've been fixed earlier
1606 - gcc-* <unknown> (embed)
1607
1608 ocamlgsl
1609 - orpie 1.5.1-7.1 (embed; bug #550058)
1610
1611 xdotool
1612 - keynav <unfixed> (embed; bug #560103)
1613
1614 bulletphysics (not packaged; http://www.bulletphysics.org/)
1615 - supertuxkart <unfixed> (embed)
1616 - blender <unfixed> (embed)
1617
1618 ghostscript
1619 - gs-gpl <removed> (old-version)
1620
1621 icedove
1622 - thunderbird <removed> (old-version)
1623
1624 sizzlejs (not packaged in Debian, http://sizzlejs.com/)
1625 - libjs-jquery <unfixed> (embed)
1626
1627 sed
1628 - ssed <unfixed> (fork)
1629
1630 phpatomlib (http://code.google.com/p/phpatomlib)
1631 - wordpress <unfixed> (embed)
1632
1633 Services_JSON (http://pear.php.net/package/Services_JSON)
1634 - wordpress <unfixed> (embed)
1635
1636 phpass (http://www.openwall.com/phpass/)
1637 - gallery2 <unfixed> (embed)
1638 - wordpress <unfixed> (embed)
1639 - typo3-src <unfixed> (fork)
1640 NOTE: file refers to drupal, maybe there's a copy somewhere there
1641 NOTE: a copyright owner search didn't match anything
1642 - libauthen-passphrase-perl <unfixable> (fork)
1643 NOTE: perl implementation of phpass
1644
1645 squirrelmail
1646 - wordpress <unfixed> (embed)
1647 NOTE: class-pop3.php
1648
1649 ezSQL (http://www.woyano.com/jv/ezsql)
1650 - wordpress <unfixable> (fork)
1651 NOTE: wp-db.php
1652
1653 Diff.php (Clay Loveless' version/killersoft.com)
1654 - php-versioncontrol-svn <unfixed>
1655
1656 libm
1657 - spring <unfixed> (embed)
1658 NOTE: embedded by embedded copy of streflop
1659
1660 streflop
1661 - spring <unfixed> (embed)
1662
1663 minizip
1664 - spring <unfixed> (embed)
1665
1666 oscpack
1667 - spring <unfixed> (embed)
1668
1669 hpiutil2
1670 - spring <unfixed> (embed)
1671
1672 p7zip
1673 - spring <unfixed> (embed)

  ViewVC Help
Powered by ViewVC 1.1.5