/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7924 by stef-guest, Mon Jan 14 23:05:37 2008 UTC revision 10237 by white, Sun Nov 2 11:11:40 2008 UTC
# Line 1  Line 1 
1  Embedded code copies  Embedded code copies
2  ====================  ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects which is considered bad for fixing security flaws  This is considered bad for fixing security flaws because the fix needs
6  because the fix needs to be applied in multiple source packages.  to be applied in multiple source packages.
7    
8  Format:  Format:
9  <srcpkg> (<optional comment about srcpkg>)  <srcpkg> (<optional comment about srcpkg>)
10          - <embedding srcpkg> <status> (<sort>; bug #<number>)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11          NOTE: optional comments about the linkage of the embedding srcpkg          NOTE: optional comments about the linkage of the embedding srcpkg
12    
13  status: version number fixing the embedded copy, <unfixed>, <removed>, <itp> or <unknown> if the version number can not be determined  status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp> or <unknown> if the version number can not be determined
15            <unfixable> for unavoidable cases (e.g., forks that add real value)
16  sort: static (linking statically against a lib)  sort: static (linking statically against a lib)
17        embed (embedding a copy of the library into another source package)        embed (embedding a copy of the library into another source package)
18        fork (the package is not just embedding code but it is a fork and thus might share parts of the source code)        fork (the package is not just embedding code but it is a fork and
19                thus might share parts of the source code)
20          old-version (the package is an older version of essentially
21                       the same code)
22    
23  The srcpkg might be some string to identify the code if there is no specific source package.  The srcpkg might be some string to identify the code if there is no
24    specific source package.
25    
26  Everything up to the next line is ignored  Everything up to the next line is ignored.
27  ---BEGIN  ---BEGIN
28  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29          NOTE: Fixed packages link to poppler library unless otherwise noted          NOTE: Fixed packages link to poppler library unless otherwise noted
# Line 30  xpdf (some srcpkgs use xpdf2 code, some Line 36  xpdf (some srcpkgs use xpdf2 code, some
36          NOTE: has been replaced by poppler-utils          NOTE: has been replaced by poppler-utils
37          - kdegraphics <unfixed> (embed; bug #436164)          - kdegraphics <unfixed> (embed; bug #436164)
38          NOTE: the kpdf replacement in KDE 4 is using poppler          NOTE: the kpdf replacement in KDE 4 is using poppler
39          - tetex-bin 3.0-12 (embed)          - texlive-base 3.0-12 (embed)
40          - texlive-bin 2007-1 (embed)          - texlive-bin 2007-1 (embed)
41          NOTE: links to poppler          NOTE: links to poppler
42          - koffice <unfixed> (embed; bug #436163)          - koffice <unfixed> (embed; bug #436163)
# Line 46  xpdf (some srcpkgs use xpdf2 code, some Line 52  xpdf (some srcpkgs use xpdf2 code, some
52  ppmd  ppmd
53          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55    peercast
56            - gnome-peercast <unfixed> (embed)
57            NOTE: gnome-peercast may better be removed, see #466539
58    
59  silc-toolkit  silc-toolkit
60          - silc-client 1.1~beta6-1 (embed)          - silc-client 1.1~beta6-1 (embed)
61    
# Line 142  pcre Line 152  pcre
152          - tf5 5.0beta7-1 (embed)          - tf5 5.0beta7-1 (embed)
153          - monotone <unfixed> (embed)          - monotone <unfixed> (embed)
154          NOTE: this only affects versions >= 0.37          NOTE: this only affects versions >= 0.37
155          - glib <unfixed> (embed)          - glib2.0 2.15.2-1 (embed)
         NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic  
156          - apache2 2.0.53-4 (embed)          - apache2 2.0.53-4 (embed)
157          - exim4 4.10-0.srh20.12 (embed)          - exim4 4.10-0.srh20.12 (embed)
158          - yacas <unfixed> (embed)          - yacas <unfixed> (embed)
159          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
160          - gtamsanalyzer.app 0.42-5 (embed)          - gtamsanalyzer.app 0.42-5 (embed)
161            - tin <unknown> (embed)
162            - kazehakase 0.5.2-1
163            - webkit <unfixed> (embed)
164            - qt4-x11 <unfixed> (embed)
165            NOTE: embedded via webkit copy
166    
167  tiff  tiff
168          - wxpythongtk <unfixed> (embed)          - wxwindows2.4 2.2.1 (embed)
         TODO: check, which debian pkg this is in  
169    
170  uudeview  uudeview
171          - libconvert-uulib-perl <unfixed> (embed)          - libconvert-uulib-perl <unfixed> (embed)
172            - pan <unfixed> (embed)
173    
174  sqlite (not affected by security vulnerabilities so far)  sqlite (not affected by security vulnerabilities so far)
175          - amarok <unfixed> (embed)          - amarok <unfixed> (embed)
# Line 185  chmlib Line 199  chmlib
199          - kchmviewer <unknown> (embed)          - kchmviewer <unknown> (embed)
200    
201  libavcodec/libavformat (source: ffmpeg)  libavcodec/libavformat (source: ffmpeg)
202          - mplayer <unfixed> (embed; bug #395252)          - mplayer 1.0~rc2-14 (embed; bug #395252)
203          - xvidcap <unfixed> (embed)          - kino 1.0.0-1
204          - kino <unfixed> (static)          - vlc <not-affected> (Links dynamically since initial release)
205          - vlc <unfixed> (static)          - smilutils 0.3.0-10
206          - smilutils <unfixed> (static)          NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
207          - motion <unfixed> (static)          - motion 3.1.19-1
208          - gst-ffmpeg <unfixed> (embed)          - gstreamer0.10-ffmpeg 0.10.3-2
         - gstreamer0.10-ffmpeg <unfixed> (embed)  
209          - xmovie <unfixed>          - xmovie <unfixed>
210          TODO: gimp-gap (potentially using ffmpeg code as well)          TODO: gimp-gap (potentially using ffmpeg code as well)
211    
# Line 225  uw-imap Line 238  uw-imap
238  imagemagick  imagemagick
239          - graphicsmagick <unfixed> (fork)          - graphicsmagick <unfixed> (fork)
240    
241    libphp-snoopy
242            - ampache <unfixed> (embed)
243            - mahara <unfixed> (embed)
244            - pixelpost <unfixed> (embed)
245    
246  halibut  halibut
247          - nsis <unfixed> (embed)          - nsis <unfixed> (embed)
248    
# Line 251  libmms Line 269  libmms
269          - mimms <unfixed> (embed)          - mimms <unfixed> (embed)
270    
271  fckeditor  fckeditor
272          - knowledgeroot <unfixed> (embed)          - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
273          - moin <unfixed> (embed; bug #452599)          - moin <unfixed> (embed; bug #452599)
274          - karrigell <unfixed> (embed; bug #452598)          - karrigell <removed> (embed; bug #452598)
275          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)
276    
277  ipatlas (not packaged in Debian)  ipatlas (not packaged in Debian)
# Line 261  ipatlas (not packaged in Debian) Line 279  ipatlas (not packaged in Debian)
279    
280  libphp-phpmailer  libphp-phpmailer
281          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
282            - mahara <unfixed> (embed)
283            - symfony <unfixed> (embed)
284            - phpgroupware-felamimail <unfixed> (embed)
285    
286  htmlArea (not packaged in Debian)  htmlArea (not packaged in Debian)
287          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
288    
289    giflib:
290            - wine <unfixed> (embed; bug #466181)
291    
292  bennu (not packaged in Debian)  bennu (not packaged in Debian)
293          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
294    
295  smarty:  smarty:
296          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #471158)
297            - gallery2 2.2.5-2 (embed; bug #471160)
298            - mahara 0.9.2-2 (embed; bug #471201)
299            - gosa 2.4beta1-1 (embed; bug #471200)
300    
301  TinyMCE  TinyMCE
302          - wordpress <unfixed> (embed)          - wordpress 2.5.1-3 (embed; bug #478257)
303          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
304          - knowledgeroot <unfixed> (embed)          - knowledgeroot <unfixed> (embed)
305          - joomla <itp> (bug #326398)          - joomla <itp> (bug #326398)
# Line 296  libphp-adodb Line 323  libphp-adodb
323          - cacti <unknown> (embed)          - cacti <unknown> (embed)
324          [sarge] - cacti <unfixed> (embed)          [sarge] - cacti <unfixed> (embed)
325          NOTE: dependency exists, but internal version is used          NOTE: dependency exists, but internal version is used
326            - gforge <unfixed> (embed)
327            - mahara <unfixed> (embed)
328    
329  gzip  gzip
330          - linux-kernel <unfixed> (embed)          - linux-kernel <unfixed> (embed)
# Line 343  libXaw Line 372  libXaw
372  libgd2  libgd2
373          - graphviz <unfixed> (embed)          - graphviz <unfixed> (embed)
374          NOTE: lib/gd seems to be 2.0.33          NOTE: lib/gd seems to be 2.0.33
375            - wml <unfixed> (embed)
376            NOTE: derived from gd 1.6.3
377    
378  rar  rar
379          - unrar-nonfree <unfixed> (embed)          - unrar-nonfree <unfixed> (embed)
# Line 364  fsplib (http://sourceforge.net/projects/ Line 395  fsplib (http://sourceforge.net/projects/
395          - gftp <unfixed> (embed)          - gftp <unfixed> (embed)
396          NOTE: lib/fsplib version 0.3          NOTE: lib/fsplib version 0.3
397    
398    sprng
399            - tree-puzzle <unfixed> (embed)
400    
401  librpcsecgss  librpcsecgss
402          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
403    
# Line 392  lzma Line 426  lzma
426  lzo  lzo
427          - grub2 <unfixed> (embed)          - grub2 <unfixed> (embed)
428    
429    yassl
430            - mysql-dfsg-5.0 <unfixed> (embed)
431    
432  pax code  pax code
433          - tar <unfixed> (embed)          - tar <unfixed> (embed)
434          - cpio <unfixed> (embed)          - cpio <unfixed> (embed)
# Line 399  pax code Line 436  pax code
436  t1lib  t1lib
437          - tetex-bin 2.0.2-1 (embed)          - tetex-bin 2.0.2-1 (embed)
438          - texlive-bin <unknown> (embed)          - texlive-bin <unknown> (embed)
439    
440    guichan
441            - boswars <unfixed> (embed)
442            NOTE: maintainer notified us, working on it
443    
444    tolua
445            - boswars <unfixed> (embed)
446            NOTE: maintainer notified us, working on it
447    
448    asio-dev
449            - luxrender <unfixed> (embed)
450            NOTE: maintainer notified us, working on it
451            NOTE: may be merged with boost "soon"
452    
453    xine-lib
454            - vlc <unfixed> (embed)
455            NOTE: only parts included in modules/access/rtsp
456    
457    netpbm
458            - tcl8.3 <unfixed> (embed)
459            - tcl8.4 <unfixed> (embed)
460            - tcl8.5 <unfixed> (embed)
461            NOTE: generic/tkImgGIF.c
462    
463    tk8.5
464            - tk8.0 <removed> (old-version)
465            - tk8.3 <unfixed> (old-version)
466            - tk8.4 <unfixed> (old-version)
467            - perl-tk <unfixable> (fork)
468    
469    samba
470            - mc <unfixed> (embed)
471            NOTE: maintainer is aware of this, currently searching a solution
472    
473    plib1.8.4c2
474            - boson <unfixed> (fork)
475            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
476    
477    fribidi
478            - quesoglc <unfixed> (embed)
479    
480    glew
481            - quesoglc <unfixed> (embed)
482    
483    minorGems
484            - transcend <unfixed> (embed)
485            - cultivation <unfixed> (embed)
486    
487    tar
488            - libarchive <unfixed> (embed)
489            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
490    
491    cpio
492            - libarchive <unfixed> (embed)
493            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
494    
495    webkit
496            - qt4-x11 <unfixed> (embed)
497    
498    ftgl
499            - blender 2.46+dfsg-1 (embed)
500    
501    wv
502            - abiword <unfixed>
503    
504    qemu
505            - kvm <unfixed> (embed)
506            - xen-3 <unfixed> (embed)
507            - xen-unstable <unfixed> (embed)
508    
509    bochs
510            - kvm <unfixed> (embed; bug #489442)
511    
512    speex
513            - vorbis-tools <unfixed> (embed)
514            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
515            - gst-plugins-good0.10 <unfixed> (embed)
516            - xine-lib <unfixed> (embed)
517            - libfishsound <unfixed> (embed)
518            - libannodex <unfixed> (embed)
519            - vlc <unfixed> (embed)
520            - xmms-speex <unfixed> (embed)
521            - libsdl-sound1.2 <unfixed> (embed)
522            - sweep <unfixed> (embed)
523    
524    libreadline
525            - magic <unfixed> (old-version)
526            NOTE: magic is currently an RFS
527    
528    opcode
529            - ode <unfixed> (embed)
530            NOTE: opcode is not a package in debian, it is just embedded
531            NOTE: http://www.codercorner.com/Opcode.htm
532    
533    gimpact
534            - ode <unfixed> (embed)
535            NOTE: gimpact is not a package in debian, it is just embedded
536            NOTE: http://gimpact.sf.net
537    
538    MochiKit.js
539            - mahara <unfixed> (embed)
540            NOTE: they require extra patches, still unmerged upstream
541            - ntop <unfixed> (embed)
542            - python-oherence <unfixed> (embed)
543            - python-paste <unfixed> (embed)
544            - python-turbogears <unfixed> (embed)
545            - zope-plone3 <unfixed> (embed)
546    
547    prototype.js
548            - netbeans-ide <unfixed> (embed)
549            - auth2db-frontend <unfixed> (embed)
550            - citadel-webcit <unfixed> (embed)
551            - asterisk <unfixed> (embed)
552            - doc-iana <unfixed> (embed)
553            - libaws-doc <unfixed> (embed)
554            - libgettext-ruby-data <unfixed> (embed)
555            - libjson-ruby-doc <unfixed> (embed)
556            - liblucene2-java-doc <unfixed> (embed)
557            - libopenid-ruby <unfixed> (embed)
558            - solr-common <unfixed> (embed)
559            - glpi <unfixed> (embed)
560            - hobbix <unfixed> (embed)
561            - mnemo2 <unfixed> (embed)
562            - nag2 <unfixed> (embed)
563            - libjs-prototype <unfixed> (embed)
564            - libjs-scriptaculous <unfixed> (embed)
565            - knowledgeroot <unfixed> (embed)
566            - mediatomb-common <unfixed> (embed)
567            - mt-daapd <unfixed> (embed)
568            - op-panel <unfixed> (embed)
569            - ebug-http <unfixed> (embed)
570            - phpgedview <removed> (embed)
571            - poker-web <unfixed> (embed)
572            - python-webhelpers <unfixed> (embed)
573            - qwik <unfixed> (embed)
574            - rails <unfixed> (embed)
575            - typo3-src-4.1 <unfixed> (embed)
576            - wordpress <unfixed> (embed)
577            - zope-plone3 <unfixed> (embed)
578            - smokeping <unfixed> (embed)
579            - ampache <unfixed> (embed)
580            - exaile <unfixed> (embed)
581            - hobix <unfixed> (embed)
582            - pixelpost <unfixed> (embed)
583            - symfony <unfixed> (embed)
584            NOTE: it's been said that there are custom changes
585            - zabbix-frontend-php <unfixed> (embed)
586    
587    gdb
588            - insight <unfixed> (embed)
589    
590    e2fsprogs
591            - ldiskfsprogs <unfixable> (fork)
592    
593    quazip (not packaged in Debian)
594            - qcake <unfixed> (embed)
595            NOTE: starting with upstream version 0.6.4
596    
597    exo
598            - pcmanfm <unfixed> (embed; bug #499677)
599            NOTE: slightly modified source code
600    
601    java
602            - openjdk-6 <unfixed>
603            - sun-java5 <unfixed>
604            - sun-java6 <unfixed>
605    
606    libphp-snoopy
607            - ampache 3.4.1-2 (embed; bug #504169)
608            - mahara <unfixed> (embed; bug #504170)
609            - pixelpost <unfixed> (embed; bug #504171)
610            - mediamate 0.9.3.6-5 (embed; bug #504172)
611            - opendb <unfixed> (embed; bug #504173)
612            - wordpress <unfixed> (embed; bug #443948)
613            - moodle <unfixed> (embed)
614            - phpgroupware-felamimail <unfixed> (embed)
615            - magpierss 0.72-3 (embed; bug #431089)
616    
617    jquery.js
618            - zekr <unfixed> (embed)
619    
620    kses
621            - wordpress <unfixed> (embed; bug #504242)
622            NOTE: their copy has all methods renamed to wp_<foo>
623            - moodle <unfixed> (embed)
624            - egroupware-core <unfixed> (embed)
625    
626    magpierss
627            - wordpress <unfixed> (embed; bug #504242)
628    
629    php-gettext
630            - wordpress <unfixed> (embed; bug #504242)
631    
632    libphp-ixr (name may change, it is the Incutio XML-RPC)
633            - wordpress <unfixed> (embed; bug #504242)
634            - dokuwiki <unfixed> (embed)
635            - textpattern <unfixed> (embed)

Legend:
Removed from v.7924  
changed lines
  Added in v.10237

  ViewVC Help
Powered by ViewVC 1.1.5