/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 2068 by jmm-guest, Wed Sep 21 08:53:12 2005 UTC revision 10511 by white, Fri Nov 28 22:40:51 2008 UTC
# Line 1  Line 1 
1  This file collects cases, where a source package embeds code from  Embedded code copies
2  other projects, without linking dynamically:  ====================
3    
4  xpdf code: (some use xpdf 2, some xpdf 3)  This file collects source packages that embed code from other projects.
5  gpdf  This is considered bad for fixing security flaws because the fix needs
6  pdftohtml  to be applied in multiple source packages.
7  kdegraphics/kpdf  
8  tetex-bin  Format:
9  cupsys (only older releases, recent ones use xpdf-utils, it's still present in the src, though)  <srcpkg> (<optional comment about srcpkg>)
10  poppler          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11            NOTE: optional comments about the linkage of the embedding srcpkg
12    
13    status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp> or <unknown> if the version number can not be determined
15            <unfixable> for unavoidable cases (e.g., forks that add real value)
16    sort: static (linking statically against a lib)
17          embed (embedding a copy of the library into another source package)
18          fork (the package is not just embedding code but it is a fork and
19                thus might share parts of the source code)
20          old-version (the package is an older version of essentially
21                       the same code)
22    
23    The srcpkg might be some string to identify the code if there is no
24    specific source package.
25    
26    Everything up to the next line is ignored.
27    ---BEGIN
28    xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29            NOTE: Fixed packages link to poppler library unless otherwise noted
30            - gpdf <removed>
31            [sarge] - gpdf <unfixed>
32            NOTE: has been replaced by evince in etch
33            - pdftohtml <unknown>
34            [sarge] - pdftohtml <unfixed>
35            [etch] - pdftohtml <unfixed>
36            NOTE: has been replaced by poppler-utils
37            - kdegraphics <unfixed> (embed; bug #436164)
38            NOTE: the kpdf replacement in KDE 4 is using poppler
39            - texlive-base 3.0-12 (embed)
40            - texlive-bin 2007-1 (embed)
41            NOTE: links to poppler
42            - koffice <unfixed> (embed; bug #436163)
43            - libextractor 0.5.12-1 (embed)
44            NOTE: libextractor is using its own pdf decoder now
45            - libextractor 0.5.12-1 (embed)
46            - pdfkit.framework 0.8-4 (embed)
47            - ipe <unfixed> (embed)
48            NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
49            - ruby-gnome2 <unknown> (embed)
50            NOTE: copy only present in source but links to poppler
51    
52    ppmd
53            - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55    peercast
56            - gnome-peercast <unfixed> (embed)
57            NOTE: gnome-peercast may better be removed, see #466539
58    
59    silc-toolkit
60            - silc-client 1.1~beta6-1 (embed)
61    
62    dietlibc
63            - ccontrol 0.9.1+20071204-1 (static)
64    
65    libiax
66            - iaxmodem <unfixed> (embed)
67    
68    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
69            - dpkg <unfixed> (embed)
70            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
71            - rsync <unfixed> (embed)
72            NOTE: somehow derived code base
73            - mono <unfixed> (embed)
74            TODO: check mozilla
75            - Linux kernels <unfixed> (embed)
76            - pvpgn 1.7.8-2 (embed)
77            - mrtg 2.12.2-1 (embed)
78            - rpm <unknown> (embed)
79            NOTE: pinged anibal since when rpm was fixed
80    
81    libbz2
82            - dpkg <unfixed> (static)
83    
84    libgadu:
85            - centericq <unfixed> (embed)
86            - gaim <unfixed> (embed)
87            - pidgin <unfixed> (embed)(links dynamically against libgadu) (that should be fixed, then???)
88            - kopete 4:3.3.2-5 (embed)
89            - kadu 0.6.0.2-3 (embed)
90            - gadu <unfixed> (embed)
91            - ekg 1:1.8~rc0-1 (embed)
92            - kadu 0.6.0.2-3 (embed; bug #504430)
93            NOTE: gadu not packaged in Debian yet
94    
95    xmlrpc (which package is the "origin" of this code?)
96            - drupal <unfixed> (embed)
97            - phpgroupware <unfixed> (embed)
98            - egroupware <unfixed> (embed)
99            - phpwiki (embed)
100            - php4 <unfixed> (embed)
101            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
102    
103    shtool (affects build-time only)
104            - mysql-ocaml <unfixed> (embed)
105            - php4 <unfixed> (embed)
106    
107    mozilla source code
108            - mozilla-firefox <unfixed> (embed)
109            - mozilla-thunderbird
110            - firefox <removed>
111            [etch] - firefox <unfixed> (embed)
112            - thunderbird <removed>
113            [etch] - thunderbird <unfixed> (embed)
114            - iceweasel <unfixed> (embed)
115            - iceape <unfixed> (embed)
116            - icedove <unfixed> (embed)
117            - xulrunner <unfixed> (embed)
118            - nvu <removed> (embed)
119    
120    xli
121            - xloadimage <unfixed> (embed)
122    
123    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
124            - openmotif <unfixed> (embed)
125            - xfree86/xorg <unfixed> (embed)
126            NOTE: in libxpm
127    
128    kerberized apps with BSD origin
129            - krb4 <unfixed> (embed)
130            - krb5 <unfixed> (embed)
131            - heimdal <unfixed> (embed)
132    
133    grip (which pkg is the origin?)
134            - libcdaudio
135            - grip
136            - gnome-vfs
137            TODO: check vfs2 as well
138    
139    fudforum
140            - phpgroupware-fudforum <unfixed> (embed)
141            - egroupware-fudforum <removed>
142            [sarge] - egroupware-fudforum <unfixed> (embed)
143    
144    cvs
145            - gcvs <unfixed> (embed)
146            NOTE: see cvsunix/src in tarball
147    
148    pcre
149            - python* <unfixed> (embed)
150            - php4 <unknown> (embed)
151            - analog 2:5.23-0woody1 (embed)
152            - libgoffice-1 <unfixed> (embed)
153            - vfu 4.06-4.1 (embed; bug #450754)
154            - tf5 5.0beta7-1 (embed)
155            - monotone <unfixed> (embed)
156            NOTE: this only affects versions >= 0.37
157            - glib2.0 2.15.2-1 (embed)
158            - apache2 2.0.53-4 (embed)
159            - exim4 4.10-0.srh20.12 (embed)
160            - yacas <unfixed> (embed)
161            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
162            - gtamsanalyzer.app 0.42-5 (embed)
163            - tin <unknown> (embed)
164            - kazehakase 0.5.2-1
165            - webkit <unfixed> (embed)
166            - qt4-x11 <unfixed> (embed)
167            NOTE: embedded via webkit copy
168    
169    tiff
170            - wxwindows2.4 2.2.1 (embed)
171    
172    uudeview
173            - libconvert-uulib-perl <unfixed> (embed)
174            - pan <unfixed> (embed)
175    
176    sqlite (not affected by security vulnerabilities so far)
177            - amarok <unfixed> (embed)
178            - monotone <unfixed> (embed)
179            - iceweasel <unfixed> (embed)
180    
181    util-linux/mount
182            - loop-aes-utils <unfixed> (embed)
183            NOTE: contains code from util-linux' mount in the mount-aes-udeb
184    
185    webmin
186            - usermin <unknown> (embed)
187            [sarge] - usermin <unfixed> (embed)
188    
189    sylpheed
190            - sylpheed-claws <unfixed> (fork)
191    
192    phpsysinfo
193            - egroupware <unfixed> (embed)
194            - phpgroupware <unfixed> (embed)
195    
196    phpldapadmin
197            [sarge] - egroupware <unfixed> (embed)
198            NOTE: removed from egroupware after sarge
199    
200    chmlib
201            - kchmviewer <unknown> (embed)
202    
203    libavcodec/libavformat (source: ffmpeg)
204            - mplayer 1.0~rc2-14 (embed; bug #395252)
205            - kino 1.0.0-1
206            - vlc <not-affected> (Links dynamically since initial release)
207            - smilutils 0.3.0-10
208            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
209            - motion 3.1.19-1
210            - gstreamer0.10-ffmpeg 0.10.3-2
211            - xmovie <unfixed>
212            TODO: gimp-gap (potentially using ffmpeg code as well)
213    
214    mad MPEG decoding lib
215            - mad <unfixed> (embed)
216            - xine-lib <unfixed> (embed)
217    
218    libdts
219            - xine-lib <unfixed> (embed)
220    
221    flac
222            - xine-lib <unfixed> (embed)
223    
224    liba52
225            - a52dec <unfixed> (embed)
226            - xine-lib <unfixed> (embed)
227    
228    libmpeg2
229            - mpeg2dec <unfixed> (embed)
230            - xine-lib <unfixed> (embed)
231    
232    curl
233            - wget <unfixed> (embed)
234            NOTE: code for NTLM authentication
235    
236    uw-imap
237            - pine <unfixed> (embed)
238            - alpine <unfixed> (embed)
239    
240    imagemagick
241            - graphicsmagick <unfixed> (fork)
242    
243    
244    halibut
245            - nsis <unfixed> (embed)
246    
247    libghttp
248            - hotway <unfixed> (embed)
249    
250    libsndfile
251            - ardour <unfixed> (embed)
252    
253    glibmm2.4
254            - ardour <unfixed> (embed)
255    
256    libgnomecanvasmm2.6
257            - ardour <unfixed> (embed)
258    
259    libsigc++-2.0
260            - ardour <unfixed> (embed)
261    
262    soundtouch
263            - ardour <unfixed> (embed)
264    
265    libmms
266            - xine-lib <unfixed> (embed)
267            - mimms <unfixed> (embed)
268    
269    fckeditor
270            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
271            - moin <unfixed> (embed; bug #452599)
272            - karrigell <removed> (embed; bug #452598)
273            - gforge 4.6.99+svn6225-1 (embed)
274    
275    ipatlas (not packaged in Debian)
276            - moodle <unfixed> (embed; bug #507185)
277    
278    libphp-phpmailer
279            - moodle <unfixed> (embed; bug #507185)
280            - mahara <unfixed> (embed)
281            - symfony <unfixed> (embed)
282            - phpgroupware-felamimail <unfixed> (embed)
283            NOTE: phpgroupware-felamimail is only in etch
284            - egroupware <unfixed> (embed; bug #504283)
285    
286    htmlArea (not packaged in Debian)
287            - moodle <unfixed> (embed)
288    
289    giflib:
290            - wine <unfixed> (embed; bug #466181)
291    
292    bennu (not packaged in Debian)
293            - moodle <unfixed> (embed)
294    
295    smarty:
296            - moodle 1.8.2-2 (embed; bug #471158)
297            - gallery2 2.2.5-2 (embed; bug #471160)
298            - mahara 0.9.2-2 (embed; bug #471201)
299            - gosa 2.4beta1-1 (embed; bug #471200)
300    
301    TinyMCE
302            - wordpress 2.5.1-3 (embed; bug #478257)
303            - moodle <unfixed> (embed; bug #507185)
304            - knowledgeroot <unfixed> (embed)
305            - joomla <itp> (bug #326398)
306    
307    scintilla
308            - scite <unfixed> (embed)
309            - qscintilla <unfixed> (embed)
310            - qscintilla2 <unfixed> (embed)
311            - geany <unfixed> (embed)
312    
313    libphp-adodb
314            - moodle <unfixed> (embed; bug #507185)
315            NOTE: also AdoDB-XML Schema
316            - gallery2 <unfixed> (embed)
317            - phppgadmin <unfixed> (embed)
318            - egroupware <unfixed> (embed)
319            - phpwiki <unfixed> (embed)
320            - ipplan <unfixed> (embed)
321            - typo3 <unfixed> (embed)
322            - cacti <unknown> (embed)
323            [sarge] - cacti <unfixed> (embed)
324            NOTE: dependency exists, but internal version is used
325            - gforge 4.7~rc2-6 (embed)
326            - mahara <unfixed> (embed)
327    
328    gzip
329            - linux-kernel <unfixed> (embed)
330            NOTE: lib/inflate.c
331            - klibc <unfixed> (embed)
332            NOTE: based on linux-kernel gzip code
333            - busybox <unfixed> (embed)
334    
335    neon
336            - cadaver <unfixed> (embed; bug #188381)
337            - gnome-vfs2 <unfixed> (embed; bug #395874)
338            - litmus <unfixed> (embed; #395875)
339            [sarge] - screem <unfixed> (embed)
340            - sitecopy <unfixed> (embed; bug #395876)
341            [etch] - tla <unfixed> (embed; bug #395877)
342            [sarge] - tla <unfixed> (embed; bug #395877)
343    
344    libmodplug
345            - gst-plugins-bad0.10 <unfixed> (embed)
346    
347    libvncserver
348            - vino <unfixed> (embed)
349    
350    putty
351            - filezilla <unfixed> (embed)
352    
353    tinyxml (not packaged in Debian)
354            - filezilla <unfixed>
355    
356    gv
357            - evince <unfixed> (embed)
358            NOTE: ps/ tree from gv 3.5.8
359            - evince-gtk <unfixed> (embed)
360            NOTE: not packaged in Debian
361    
362    libXbae
363            [etch] - libpawlib2-lesstif <unfixed> (embed)
364            NOTE: from Cernlib
365    
366    libXaw
367            [etch] - libpawlib2-lesstif
368            NOTE: from Cernlib
369            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
370    
371    libgd2
372            - graphviz <unfixed> (embed)
373            NOTE: lib/gd seems to be 2.0.33
374            - wml <unfixed> (embed)
375            NOTE: derived from gd 1.6.3
376    
377    rar
378            - unrar-nonfree <unfixed> (embed)
379    
380    unrar-free (maybe this code is derived from the original rar, too?)
381            - clamav <unfixed> (embed)
382            NOTE: seems to be disabled in default config
383    
384    mplayer (DirectMedia Object loader)
385            - xine-lib <unfixed> (embed)
386            NOTE: src/libw32dll/
387            - vlc <unfixed> (embed)
388            NOTE: modules/codec/dmo/
389    
390    libwpd (WordPerfect converter)
391            - openoffice.org <unfixed> (embed)
392    
393    fsplib (http://sourceforge.net/projects/fsp/)
394            - gftp <unfixed> (embed)
395            NOTE: lib/fsplib version 0.3
396    
397    sprng
398            - tree-puzzle <unfixed> (embed)
399    
400    librpcsecgss
401            - krb5 <unfixed> (embed)
402    
403    jasper
404            - ghostscript <unfixed> (embed)
405            - gs-gpl <unfixed> (embed)
406    
407    libidn
408            - monotone <unfixed> (embed)
409    
410    liblua
411            - monotone <unfixed> (embed)
412    
413    libbotan
414            - montone <unfixed> (embed)
415    
416    NetXX
417            - monotone <unfixed> (embed)
418    
419    libgc
420            - mono <unfixed> (embed)
421    
422    lzma
423            - p7zip <unfixed> (embed)
424    
425    lzo
426            - grub2 <unfixed> (embed)
427    
428    yassl
429            - mysql-dfsg-5.0 <unfixed> (embed)
430    
431    pax code
432            - tar <unfixed> (embed)
433            - cpio <unfixed> (embed)
434    
435    t1lib
436            - tetex-bin 2.0.2-1 (embed)
437            - texlive-bin <unknown> (embed)
438    
439    guichan
440            - boswars <unfixed> (embed)
441            NOTE: maintainer notified us, working on it
442    
443    tolua
444            - boswars <unfixed> (embed)
445            NOTE: maintainer notified us, working on it
446    
447    asio-dev
448            - luxrender <unfixed> (embed)
449            NOTE: maintainer notified us, working on it
450            NOTE: may be merged with boost "soon"
451    
452    xine-lib
453            - vlc <unfixed> (embed)
454            NOTE: only parts included in modules/access/rtsp
455    
456    netpbm
457            - tcl8.3 <unfixed> (embed)
458            - tcl8.4 <unfixed> (embed)
459            - tcl8.5 <unfixed> (embed)
460            NOTE: generic/tkImgGIF.c
461    
462    tk8.5
463            - tk8.0 <removed> (old-version)
464            - tk8.3 <unfixed> (old-version)
465            - tk8.4 <unfixed> (old-version)
466            - perl-tk <unfixable> (fork)
467    
468    samba
469            - mc <unfixed> (embed)
470            NOTE: maintainer is aware of this, currently searching a solution
471    
472    plib1.8.4c2
473            - boson <unfixed> (fork)
474            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
475    
476    fribidi
477            - quesoglc <unfixed> (embed)
478    
479    glew
480            - quesoglc <unfixed> (embed)
481    
482    minorGems
483            - transcend <unfixed> (embed)
484            - cultivation <unfixed> (embed)
485    
486    tar
487            - libarchive <unfixed> (embed)
488            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
489    
490    cpio
491            - libarchive <unfixed> (embed)
492            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
493    
494    webkit
495            - qt4-x11 <unfixed> (embed)
496    
497    ftgl
498            - blender 2.46+dfsg-1 (embed)
499    
500    wv
501            - abiword <unfixed>
502    
503    qemu
504            - kvm <unfixed> (embed)
505            - xen-3 <unfixed> (embed)
506            - xen-unstable <unfixed> (embed)
507    
508    bochs
509            - kvm <unfixed> (embed; bug #489442)
510    
511    speex
512            - vorbis-tools <unfixed> (embed)
513            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
514            - gst-plugins-good0.10 <unfixed> (embed)
515            - xine-lib <unfixed> (embed)
516            - libfishsound <unfixed> (embed)
517            - libannodex <unfixed> (embed)
518            - vlc <unfixed> (embed)
519            - xmms-speex <unfixed> (embed)
520            - libsdl-sound1.2 <unfixed> (embed)
521            - sweep <unfixed> (embed)
522    
523    libreadline
524            - magic <unfixed> (old-version)
525            NOTE: magic is currently an RFS
526    
527    opcode
528            - ode <unfixed> (embed)
529            NOTE: opcode is not a package in debian, it is just embedded
530            NOTE: http://www.codercorner.com/Opcode.htm
531    
532    gimpact
533            - ode <unfixed> (embed)
534            NOTE: gimpact is not a package in debian, it is just embedded
535            NOTE: http://gimpact.sf.net
536    
537    mochikit
538            - mahara <unfixed> (embed)
539            NOTE: they require extra patches, still unmerged upstream
540            - ntop <unfixed> (embed)
541            - python-oherence <unfixed> (embed)
542            - python-paste <unfixed> (embed)
543            - python-turbogears <unfixed> (embed)
544            - zope-plone3 <unfixed> (embed)
545    
546    prototype
547            - netbeans-ide <unfixed> (embed)
548            - auth2db-frontend <unfixed> (embed)
549            - citadel-webcit <unfixed> (embed)
550            - asterisk <unfixed> (embed)
551            - doc-iana <unfixed> (embed)
552            - libaws-doc <unfixed> (embed)
553            - libgettext-ruby-data <unfixed> (embed)
554            - libjson-ruby-doc <unfixed> (embed)
555            - liblucene2-java-doc <unfixed> (embed)
556            - libopenid-ruby <unfixed> (embed)
557            - solr-common <unfixed> (embed)
558            - glpi <unfixed> (embed)
559            - hobbix <unfixed> (embed)
560            - mnemo2 <unfixed> (embed)
561            - nag2 <unfixed> (embed)
562            - knowledgeroot <unfixed> (embed)
563            - mediatomb-common <unfixed> (embed)
564            - mt-daapd <unfixed> (embed)
565            - op-panel <unfixed> (embed)
566            - ebug-http <unfixed> (embed)
567            - phpgedview <removed> (embed)
568            - poker-web <unfixed> (embed)
569            - python-webhelpers <unfixed> (embed)
570            - qwik <unfixed> (embed)
571            - rails <unfixed> (embed)
572            - typo3-src-4.1 <unfixed> (embed)
573            - wordpress <unfixed> (embed)
574            - zope-plone3 <unfixed> (embed)
575            - smokeping <unfixed> (embed)
576            - ampache 3.4.1-2 (embed)
577            - exaile <unfixed> (embed)
578            - hobix <unfixed> (embed)
579            - pixelpost <unfixed> (embed)
580            - symfony <unfixed> (embed)
581            NOTE: it's been said that there are custom changes
582            - zabbix-frontend-php <unfixed> (embed)
583            - turba2 <unfixed> (embed)
584    
585    gdb
586            - insight <unfixed> (embed)
587    
588    e2fsprogs
589            - ldiskfsprogs <unfixable> (fork)
590    
591    quazip (not packaged in Debian)
592            - qcake <unfixed> (embed)
593            NOTE: starting with upstream version 0.6.4
594    
595    exo
596            - pcmanfm <unfixed> (embed; bug #499677)
597            NOTE: slightly modified source code
598    
599    java
600            - openjdk-6 <unfixed>
601            - sun-java5 <unfixed>
602            - sun-java6 <unfixed>
603    
604    libphp-snoopy
605            - ampache 3.4.1-2 (embed; bug #504169)
606            - mahara 1.0.5-2 (embed; bug #504170)
607            - pixelpost <unfixed> (embed; bug #504171)
608            - mediamate 0.9.3.6-5 (embed; bug #504172)
609            - opendb <unfixed> (embed; bug #504173)
610            - wordpress 2.5.1-9 (embed; bug #443948)
611            - moodle <unfixed> (embed; bug #507185)
612            - phpgroupware-felamimail <unfixed> (embed)
613            NOTE: phpgroupware-felamimail is only in etch
614            - magpierss 0.72-3 (embed; bug #431089)
615    
616    jquery
617            - zekr <unfixed> (embed)
618            - wordpress <unfixed> (embed)
619            - yocto-reader <unfixed> (embed)
620            - textpattern <unfixed> (embed)
621            - genshi <unfixed> (embed)
622            NOTE: compressed file under examples/ dir
623            - prewikka <unfixed> (embed)
624            - libramaze-ruby <unfixed> (embed)
625            - drupal5 <unfixed> (embed)
626            - b2evolution <unfixed> (embed)
627    
628    kses
629            - wordpress <unfixed> (embed; bug #504242)
630            NOTE: their copy has all methods renamed to wp_<foo>
631            - moodle <unfixed> (embed; bug #507185)
632            - egroupware-core <unfixed> (embed)
633    
634    magpierss
635            - wordpress <unfixed> (embed; bug #504242)
636    
637    php-gettext
638            - wordpress <unfixed> (embed; bug #504242)
639    
640    libphp-ixr (name may change, it is the Incutio XML-RPC)
641            - wordpress <unfixed> (embed; bug #504242)
642            - dokuwiki <unfixed> (embed)
643            - textpattern <unfixed> (embed)
644    
645    domxml-php4-to-php5.php
646            - glpi <unfixed> (embed)
647            - moodle <unfixed> (embed; bug #496069)
648    
649    scriptaculous
650            - glpi <unfixed> (embed)
651            - libaws-doc <unfixed> (embed)
652            - op-panel <unfixed> (embed)
653            - symfony <unfixed> (embed)
654            NOTE: maintainer says there are extra incompatible changes required
655            - pixelpost <unfixed> (embed)
656            - python-webhelpers <unfixed> (embed)
657            - qwik <unfixed> (embed)
658            - smokeping <unfixed> (embed)
659            - turba2 <unfixed> (embed)
660            - typo3-src 4.2.3-1 (embed)
661    
662    libmarkdown-php
663            - moodle <unfixed> (embed; bug #507185)
664            - pixelpost <unfixed> (embed)
665    
666    php-openid
667            - wordpress-openid <itp> (embed)
668    
669    geshi
670            - dokuwiki 0.0.20080505-3.1 (embed)
671            - pgfouine 1.0-1.1 (embed)
672    
673    webcalendar
674            - gforge-plugins-extra 4.7~rc2-6 (embed; bug #504758)
675    
676    libical
677            - kdepim <unfixed> (fork)
678            - kdepimlibs <unfixed> (fork)
679            NOTE: fixed in KDE4 post 4.1.x series
680    
681    libltdl3
682            - kdelibs <unfixed> (embed)
683            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
684    
685  zlib code: (separate between 1.2 and 1.1)  harfbuzz
686  dpkg          - qt4-x11 <unfixed> (embed)
 rsync  
 mozilla-firefox  
 mozilla(?)  
 Linux kernels  
   
   
 libgadu/ekg:  
 centericq  
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not packaged in Debian)  
   
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki (not packaged in Debian)  
   
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 nvu  
   
   
 xli:  
 xloadimage  
   
   
 lesstif: (beware: two different lesstif APIs supported in one package, 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm, still the case with x.org?  
   
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum  
   
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 python  
 php4 (src included, but Debian package links dynamically)  
 analog (src included, but Debian package links dynamically)  
 libgoffice-1  
 tf5 (since 5.0beta7 the Debian package links dynamically)  
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
   
 uudeview:  
 libconvert-uulib-perl  
   
 sqlite: (not affected by security vulnerabilities so far)  
 amarok  
   
 uudeview:  
 libconvert-uulib-perl  
   
 util-linux/mount:  
 loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb  

Legend:
Removed from v.2068  
changed lines
  Added in v.10511

  ViewVC Help
Powered by ViewVC 1.1.5