/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 1824 by jmm-guest, Tue Sep 6 07:54:13 2005 UTC revision 11863 by pabs, Sun May 10 05:38:11 2009 UTC
# Line 1  Line 1 
1  This file collects cases, where a source package embeds code from  Embedded code copies
2  other projects, without linking dynamically:  ====================
3    
4  xpdf code: (some use xpdf 2, some xpdf 3)  This file collects source packages that embed code from other projects.
5  gpdf  This is considered bad for fixing security flaws because the fix needs
6  pdftohtml  to be applied in multiple source packages.
7  kdegraphics/kpdf  
8  tetex-bin  Format:
9  cupsys (only older releases, recent ones use xpdf-utils, it's still present in the src, though)  <srcpkg> (<optional comment about srcpkg>)
10  poppler          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11            NOTE: optional comments about the linkage of the embedding srcpkg
12    
13    status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp> or <unknown> if the version number can not be determined
15            <unfixable> for unavoidable cases (e.g., forks that add real value)
16    sort: static (linking statically against a lib)
17          embed (embedding a copy of the library into another source package)
18          fork (the package is not just embedding code but it is a fork and
19                thus might share parts of the source code)
20          old-version (the package is an older version of essentially
21                       the same code)
22    
23    The srcpkg might be some string to identify the code if there is no
24    specific source package.
25    
26    Everything up to the next line is ignored.
27    ---BEGIN
28    xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29            NOTE: Fixed packages link to poppler library unless otherwise noted
30            - gpdf <removed>
31            [sarge] - gpdf <unfixed>
32            NOTE: has been replaced by evince in etch
33            - pdftohtml <unknown>
34            [sarge] - pdftohtml <unfixed>
35            [etch] - pdftohtml <unfixed>
36            NOTE: has been replaced by poppler-utils
37            - kdegraphics 4:4.2.2-1 (embed; bug #436164)
38            - texlive-base 3.0-12 (embed)
39            - texlive-bin 2007-1 (embed)
40            NOTE: links to poppler
41            - koffice <unfixed> (embed; bug #436163)
42            - libextractor 0.5.12-1 (embed)
43            NOTE: libextractor is using its own pdf decoder now
44            - pdfkit.framework 0.8-4 (embed)
45            - ipe <unfixed> (embed)
46            NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
47            - ruby-gnome2 <unknown> (embed)
48            NOTE: copy only present in source but links to poppler
49            - pdfedit <unfixed> (embed; bug #510794)
50            - swftools <unfixed> (embed)
51    
52    ppmd
53            - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55    peercast
56            - gnome-peercast <unfixed> (embed)
57            NOTE: gnome-peercast may better be removed, see #466539
58    
59    silc-toolkit
60            - silc-client 1.1~beta6-1 (embed)
61    
62    icclib
63            - ghostscript <unfixed> (embed)
64            - argyll <unfixed> (embed)
65    
66    dietlibc
67            - ccontrol 0.9.1+20071204-1 (static)
68    
69    libmikmod
70            - sdl-mixer1.2 <unfixed> (embed)
71            TODO: report bug
72    
73    libiax
74            - iaxmodem <unfixed> (embed)
75    
76    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
77            - dpkg <unfixed> (embed)
78            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
79            - rsync <unfixed> (embed)
80            NOTE: somehow derived code base
81            - mono <unfixed> (embed)
82            TODO: check mozilla
83            - Linux kernels <unfixed> (embed)
84            - pvpgn 1.7.8-2 (embed)
85            - mrtg 2.12.2-1 (embed)
86            - rpm <unknown> (embed)
87            NOTE: pinged anibal since when rpm was fixed
88            - tuxcmd-modules <unfixed> (embed)
89            - zsync <unfixed>
90            - tra <unfixed>
91            - sash <unfixed>
92            - nsis <unfixed>
93            - mseide-msegui <unfixed>
94            NOTE: mseide
95            - mirrordir <unfixed>
96            - poco <unfixed>
97            - klibc <unfixed>
98            - ghostscript <unfixed>
99            - freeimage <unfixed>
100            - clamav <unfixed> (fork)
101            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
102            - tuxonice-userui <unfixed>
103            - plt-scheme <unfixed>
104            - perl <unfixed>
105            - paraview <unfixed>
106            - gcvs <unfixed>
107            - erlang <unfixed>
108            - dump <unfixed>
109            - aide <unfixed> (static)
110            - dar <unfixed> (static)
111            - avfs <unfixed>
112            - fpc <unfixed>
113            - winff <unfixed>
114            NOTE: inherited from fpc, see #472304
115            - lazarus <unfixed>
116            NOTE: inherited from fpc, see #472304
117    
118    libbz2
119            - dpkg <unfixed> (static)
120    
121    libgadu:
122            - centericq <unfixed> (embed)
123            - gaim <unfixed> (embed)
124            - pidgin <unfixed> (embed)(links dynamically against libgadu) (that should be fixed, then???)
125            - kdenetwork 4:3.3.2-5 (embed)
126            NOTE: from kdenetwork: kopete
127            - gadu <unfixed> (embed)
128            - ekg 1:1.8~rc0-1 (embed)
129            - kadu 0.6.0.2-3 (embed; bug #504430)
130            NOTE: gadu not packaged in Debian yet
131    
132    xmlrpc (which package is the "origin" of this code?)
133            - drupal <unfixed> (embed)
134            - phpgroupware <unfixed> (embed)
135            - egroupware <unfixed> (embed)
136            - phpwiki <unfixed> (embed)
137            - php4 <unfixed> (embed)
138            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
139    
140    shtool (affects build-time only)
141            - mysql-ocaml <unfixed> (embed)
142            - php4 <unfixed> (embed)
143    
144    mozilla source code
145            - mozilla-firefox <unfixed> (embed)
146            - mozilla-thunderbird <unfixed>
147            - firefox <removed>
148            - thunderbird <removed>
149            - iceweasel <unfixed> (embed)
150            - iceape <unfixed> (embed)
151            - icedove <unfixed> (embed)
152            - xulrunner <unfixed> (embed)
153            - nvu <removed> (embed)
154    
155    xli
156            - xloadimage <unfixed> (embed)
157    
158    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
159            - openmotif <unfixed> (embed)
160            - libxpm <unfixed> (embed)
161    
162    kerberized apps with BSD origin
163            - krb4 <unfixed> (embed)
164            - krb5 <unfixed> (embed)
165            - heimdal <unfixed> (embed)
166    
167    grip (which pkg is the origin?)
168            - libcdaudio <unfixed>
169            - grip <unfixed>
170            - gnome-vfs <unfixed>
171            TODO: check vfs2 as well
172    
173    fudforum
174            [etch] - phpgroupware <unfixed> (embed)
175            NOTE: phpgroupware-fudforum
176            [sarge] - egroupware-fudforum <removed> (embed)
177    
178    cvs
179            - gcvs <unfixed> (embed)
180            NOTE: see cvsunix/src in tarball
181    
182    pcre
183            - python* <unfixed> (embed)
184            - php4 <unknown> (embed)
185            - analog 2:5.23-0woody1 (embed)
186            - goffice <unfixed> (embed)
187            NOTE: libgoffice-*
188            - vfu 4.06-4.1 (embed; bug #450754)
189            - tf5 5.0beta7-1 (embed)
190            - monotone 0.43-1 (embed)
191            NOTE: this only affects versions >= 0.37
192            - glib2.0 2.15.2-1 (embed)
193            - apache2 2.0.53-4 (embed)
194            - exim4 4.10-0.srh20.12 (embed)
195            - yacas <unfixed> (embed)
196            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
197            - gtamsanalyzer.app 0.42-5 (embed)
198            - tin <unknown> (embed)
199            - kazehakase 0.5.2-1
200            - webkit <unfixed> (embed)
201            - qt4-x11 <unfixed> (embed)
202            NOTE: embedded via webkit copy
203    
204    tiff
205            - wxwindows2.4 2.2.1 (embed)
206    
207    uudeview
208            - libconvert-uulib-perl <unfixed> (embed)
209            - pan <unfixed> (embed)
210    
211    sqlite (not affected by security vulnerabilities so far)
212            - amarok <unfixed> (embed)
213            - monotone 0.43-1 (embed)
214            - iceweasel <unfixed> (embed)
215    
216    util-linux/mount
217            - loop-aes-utils <unfixed> (embed)
218            NOTE: contains code from util-linux' mount in the mount-aes-udeb
219    
220    webmin
221            - usermin <unknown> (embed)
222            [sarge] - usermin <unfixed> (embed)
223    
224    sylpheed
225            - sylpheed-claws <unfixed> (fork)
226    
227    phpsysinfo
228            - egroupware <unfixed> (embed)
229            - phpgroupware <unfixed> (embed)
230    
231    phpldapadmin
232            [sarge] - egroupware <unfixed> (embed)
233            NOTE: removed from egroupware after sarge
234    
235    chmlib
236            - kchmviewer <unknown> (embed)
237    
238    libavcodec/libavformat (source: ffmpeg)
239            - mplayer 1.0~rc2-14 (embed; bug #395252)
240            - kino 1.0.0-1
241            - vlc <not-affected> (Links dynamically since initial release)
242            - smilutils 0.3.0-10
243            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
244            - motion 3.1.19-1
245            - gstreamer0.10-ffmpeg 0.10.3-2
246            - xmovie <unfixed>
247            TODO: gimp-gap (potentially using ffmpeg code as well)
248    
249    faad2
250            - mplayer 1.0~rc2-20 (embed)
251    
252    mad MPEG decoding lib
253            - mad <unfixed> (embed)
254            - xine-lib <unfixed> (embed)
255    
256    libdts
257            - xine-lib <unfixed> (embed)
258    
259    flac
260            - xine-lib <unfixed> (embed)
261    
262    liba52
263            - a52dec <unfixed> (embed)
264            - xine-lib <unfixed> (embed)
265    
266    libmpeg2
267            - mpeg2dec <unfixed> (embed)
268            - xine-lib <unfixed> (embed)
269    
270    curl
271            - wget <unfixed> (embed)
272            NOTE: code for NTLM authentication
273    
274    uw-imap
275            - pine <unfixed> (embed)
276            - alpine <unfixed> (embed)
277    
278    imagemagick
279            - graphicsmagick <unfixed> (fork)
280    
281    halibut
282            - nsis <unfixed> (fork)
283    
284    libghttp
285            - hotway <unfixed> (embed)
286    
287    libsndfile
288            - ardour 1:2.7.1-1 (embed)
289    
290    glibmm2.4
291            - ardour 1:2.7.1-1 (embed)
292    
293    libgnomecanvasmm2.6
294            - ardour 1:2.7.1-1 (embed)
295    
296    libsigc++-2.0
297            - ardour 1:2.7.1-1 (embed)
298    
299    soundtouch
300            - ardour 1:2.7.1-1 (embed)
301    
302    libmms
303            - xine-lib <unfixed> (embed)
304            - mimms <unfixed> (embed)
305    
306    fckeditor
307            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
308            - moin 1.8.2-2 (embed; bug #452599)
309            - karrigell <removed> (embed; bug #452598)
310            - gforge 4.6.99+svn6225-1 (embed)
311    
312    ipatlas (not packaged in Debian)
313            - moodle <unfixed> (embed; bug #507185)
314    
315    libphp-phpmailer
316            - moodle <unfixed> (embed; bug #507185)
317            - mahara <unfixed> (embed)
318            - symfony <unfixed> (embed)
319            [etch] - phpgroupware <unfixed> (embed)
320            NOTE: phpgroupware-felamimail is only in etch
321            - egroupware <unfixed> (embed; bug #504283)
322            - glpi <unfixed>
323    
324    htmlArea (not packaged in Debian)
325            - moodle <unfixed> (embed)
326    
327    giflib:
328            - wine <unfixed> (embed; bug #466181)
329    
330    bennu (not packaged in Debian, http://bennu.sourceforge.net)
331            - moodle <unfixed> (embed)
332    
333    smarty:
334            - moodle 1.8.2-2 (embed; bug #471158)
335            - gallery2 2.2.5-2 (embed; bug #471160)
336            - mahara 0.9.2-2 (embed; bug #471201)
337            - gosa 2.4beta1-1 (embed; bug #471200)
338    
339    TinyMCE
340            - wordpress 2.5.1-3 (embed; bug #478257)
341            - moodle <unfixed> (embed; bug #507185)
342            - knowledgeroot <unfixed> (embed)
343            - joomla <itp> (bug #326398)
344    
345    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
346            - scite <unfixed> (embed)
347            - qscintilla <unfixed> (embed)
348            - qscintilla2 <unfixed> (embed)
349            - geany <unfixed> (fork)
350            - anjuta <unfixed> (embed)
351    
352    libphp-adodb
353            - moodle <unfixed> (embed; bug #507185)
354            NOTE: also AdoDB-XML Schema
355            - gallery2 <unfixed> (embed)
356            - phppgadmin <unfixed> (embed)
357            - egroupware <unfixed> (embed)
358            - phpwiki <unfixed> (embed)
359            - ipplan <unfixed> (embed)
360            - typo3-src <unfixed> (embed)
361            - cacti <unknown> (embed)
362            [sarge] - cacti <unfixed> (embed)
363            NOTE: dependency exists, but internal version is used
364            - gforge 4.7~rc2-6 (embed)
365            - mahara <unfixed> (embed)
366    
367    gzip
368            - linux-kernel <unfixed> (embed)
369            NOTE: lib/inflate.c
370            - klibc <unfixed> (embed)
371            NOTE: based on linux-kernel gzip code
372            - busybox <unfixed> (embed)
373    
374    neon
375            - cadaver <unfixed> (embed; bug #188381)
376            - gnome-vfs2 <unfixed> (embed; bug #395874)
377            - litmus <unfixed> (embed; #395875)
378            [sarge] - screem <unfixed> (embed)
379            - sitecopy <unfixed> (embed; bug #395876)
380            [etch] - tla <unfixed> (embed; bug #395877)
381            [sarge] - tla <unfixed> (embed; bug #395877)
382    
383    libmodplug
384            - gst-plugins-bad0.10 <unfixed> (embed)
385    
386    libvncserver
387            - vino <unfixed> (embed)
388    
389    putty
390            - filezilla <unfixed> (embed)
391    
392    tinyxml (not packaged in Debian)
393            - filezilla <unfixed>
394    
395    gv
396            - evince <unfixed> (embed)
397            NOTE: ps/ tree from gv 3.5.8
398            - evince-gtk <unfixed> (embed)
399            NOTE: not packaged in Debian
400    
401    libXbae
402            [etch] - libpawlib2-lesstif <unfixed> (embed)
403            NOTE: from Cernlib
404    
405    libXaw
406            [etch] - libpawlib2-lesstif <unfixed>
407            NOTE: from Cernlib
408            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
409    
410    libgd2
411            - graphviz <unfixed> (embed)
412            NOTE: lib/gd seems to be 2.0.33
413            - wml <unfixed> (embed)
414            - libwmf <unfixed> (embed)
415            NOTE: derived from gd 1.6.3
416    
417    rar
418            - unrar-nonfree <unfixed> (embed)
419    
420    unrar-free (maybe this code is derived from the original rar, too?)
421            - clamav <unfixed> (embed)
422            NOTE: seems to be disabled in default config
423    
424    mplayer (DirectMedia Object loader)
425            - xine-lib <unfixed> (embed)
426            NOTE: src/libw32dll/
427            - vlc <unfixed> (embed)
428            NOTE: modules/codec/dmo/
429            - mplayer 1.0~rc2-20 (embed)
430    
431    libwpd (WordPerfect converter)
432            - openoffice.org <unfixed> (embed)
433    
434    fsplib (http://sourceforge.net/projects/fsp/)
435            - gftp <unfixed> (embed)
436            NOTE: lib/fsplib version 0.3
437    
438    sprng
439            - tree-puzzle <unfixed> (embed)
440    
441    librpcsecgss
442            - krb5 <unfixed> (embed)
443    
444    jasper
445            - ghostscript <unfixed> (embed)
446            - gs-gpl <unfixed> (embed)
447    
448    libiris
449            - psi <unfixed> (embed)
450            - kdenetwork <unfixed> (embed)
451            NOTE: kopete embeds libiris but links dynamically to libidn
452            - kdegames <unfixed> (embed)
453            NOTE: ksirk/kde4
454    
455    libidn
456            - monotone 0.43-1 (embed)
457            - psi <unfixed> (embed)
458            NOTE: psi embeds libiris which embeds libidn
459            - kdegames <unfixed> (embed)
460            NOTE: kdegames/kde4 embeds libiris which embeds libidn
461    
462    liblua
463            - monotone 0.43-1 (embed)
464    
465    libbotan
466            - monotone 0.43-1 (embed)
467    
468    NetXX
469            - monotone 0.43-1 (embed)
470    
471    libgc
472            - mono <unfixed> (embed)
473    
474    lzma
475            - p7zip <unfixed> (embed)
476    
477    lzo
478            - grub2 <unfixed> (embed)
479    
480    yassl
481            - mysql-dfsg-5.0 <unfixed> (embed)
482    
483    pax code
484            - tar <unfixed> (embed)
485            - cpio <unfixed> (embed)
486    
487    t1lib
488            - tetex-bin 2.0.2-1 (embed)
489            - texlive-bin <unknown> (embed)
490    
491    guichan
492            - boswars <unfixed> (embed)
493            NOTE: maintainer notified us, working on it
494    
495    tolua
496            - boswars <unfixed> (embed)
497            NOTE: maintainer notified us, working on it
498    
499    asio-dev
500            - luxrender <unfixed> (embed)
501            NOTE: maintainer notified us, working on it
502            NOTE: may be merged with boost "soon"
503    
504    xine-lib
505            - vlc <unfixed> (embed)
506            NOTE: only parts included in modules/access/rtsp
507    
508    netpbm
509            - tcl8.3 <unfixed> (embed)
510            - tcl8.4 <unfixed> (embed)
511            - tcl8.5 <unfixed> (embed)
512            NOTE: generic/tkImgGIF.c
513    
514    tk8.5
515            - tk8.0 <removed> (old-version)
516            - tk8.3 <unfixed> (old-version)
517            - tk8.4 <unfixed> (old-version)
518            - perl-tk <unfixable> (fork)
519    
520    samba
521            - mc 2:4.6.2~git20080311-1 (embed)
522            NOTE: maintainer is aware of this, currently searching a solution
523    
524    plib1.8.4c2
525            - boson <unfixed> (fork)
526            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
527    
528    fribidi
529            - quesoglc <unfixed> (embed)
530            NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
531    
532    glew
533            - quesoglc <unfixed> (embed; bug #489341)
534            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
535    
536    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
537            - transcend <unfixed> (embed)
538            - cultivation <unfixed> (embed)
539            - passage <unfixed> (embed)
540            - gravitation <unfixed> (embed)
541    
542    tar
543            - libarchive <unfixed> (embed)
544            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
545    
546    cpio
547            - libarchive <unfixed> (embed)
548            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
549    
550    webkit
551            - qt4-x11 <unfixed> (embed)
552    
553    ftgl
554            - blender 2.46+dfsg-1 (embed)
555    
556    wv
557            - abiword <unfixed>
558    
559    qemu
560            - kvm <unfixed> (embed)
561            - xen-3 <unfixed> (embed)
562            - xen-unstable <unfixed> (embed)
563    
564    bochs
565            - kvm <unfixed> (embed; bug #489442)
566    
567    speex
568            - vorbis-tools <unfixed> (embed)
569            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
570            - gst-plugins-good0.10 <unfixed> (embed)
571            - xine-lib <unfixed> (embed)
572            - libfishsound <unfixed> (embed)
573            - libannodex <unfixed> (embed)
574            - vlc <unfixed> (embed)
575            - xmms-speex <unfixed> (embed)
576            - libsdl-sound1.2 <unfixed> (embed)
577            - sweep <unfixed> (embed)
578    
579    libreadline
580            - magic <unfixed> (old-version)
581            NOTE: magic is currently an RFS
582    
583    opcode
584            - ode <unfixed> (embed)
585            NOTE: opcode is not a package in debian, it is just embedded
586            NOTE: http://www.codercorner.com/Opcode.htm
587    
588    gimpact
589            - ode <unfixed> (embed)
590            NOTE: gimpact is not a package in debian, it is just embedded
591            NOTE: http://gimpact.sf.net
592    
593    mochikit
594            - mahara <unfixed> (embed)
595            NOTE: they require extra patches, still unmerged upstream
596            - ntop <unfixed> (embed)
597            - coherence <unfixed> (embed)
598            NOTE: python-coherence
599            - paste <unfixed> (embed)
600            NOTE: python-paste
601            - turbogears <unfixed> (embed)
602            NOTE: python-turbogears
603            - plone3 <unfixed> (embed)
604            NOTE: zope-plone3
605    
606    prototype
607            - netbeans-ide <unfixed> (embed)
608            - auth2db-frontend <unfixed> (embed)
609            - webcit <unfixed> (embed)
610            NOTE: citadel-webcit
611            - asterisk <unfixed> (embed)
612            - doc-iana <unfixed> (embed)
613            - libaws <unfixed> (embed)
614            NOTE: libaws-doc
615            - libgettext-ruby <unfixed> (embed)
616            NOTE: libgettext-ruby-data
617            - libjson-ruby <unfixed> (embed)
618            NOTE: libjson-ruby-doc
619            - lucene2 <unfixed> (embed)
620            NOTE: liblucene2-java-doc
621            - libopenid-ruby <unfixed> (embed)
622            - solr <unfixed> (embed)
623            NOTE: solr-common
624            - glpi <unfixed> (embed)
625            - hobbix <unfixed> (embed)
626            - mnemo2 <unfixed> (embed)
627            - nag2 <unfixed> (embed)
628            - knowledgeroot <unfixed> (embed)
629            - mediatomb <unfixed> (embed)
630            NOTE: mediatomb-common
631            - mt-daapd <unfixed> (embed)
632            - op-panel <unfixed> (embed)
633            - ebug-http <unfixed> (embed)
634            - phpgedview <removed> (embed)
635            - poker-network <unfixed> (embed)
636            NOTE: poker-web
637            - webhelpers <unfixed> (embed)
638            NOTE: python-webhelpers
639            - qwik <unfixed> (embed)
640            - rails <unfixed> (embed)
641            - typo3-src <unfixed> (embed)
642            - wordpress <unfixed> (embed)
643            - zope <unfixed> (embed)
644            NOTE: zope-plone3
645            - smokeping <unfixed> (embed)
646            - ampache 3.4.1-2 (embed)
647            - exaile <unfixed> (embed)
648            - hobix <unfixed> (embed)
649            - pixelpost <unfixed> (embed)
650            - symfony <unfixed> (embed)
651            NOTE: it's been said that there are custom changes
652            - zabbix <unfixed> (embed)
653            NOTE: zabbix-frontend-php
654            - turba2 <unfixed> (embed)
655    
656    gdb
657            - insight <unfixed> (embed)
658    
659    e2fsprogs
660            - ldiskfsprogs <unfixable> (fork)
661    
662    quazip (not packaged in Debian)
663            - qcake <unfixed> (embed)
664            NOTE: starting with upstream version 0.6.4
665    
666    exo
667            - pcmanfm <unfixed> (embed; bug #499677)
668            NOTE: slightly modified source code
669    
670    java
671            - openjdk-6 <unfixed>
672            - sun-java5 <unfixed>
673            - sun-java6 <unfixed>
674    
675    libphp-snoopy
676            - ampache 3.4.1-2 (embed; bug #504169)
677            - mahara 1.0.5-2 (embed; bug #504170)
678            - pixelpost <unfixed> (embed; bug #504171)
679            - mediamate 0.9.3.6-5 (embed; bug #504172)
680            - opendb <unfixed> (embed; bug #504173)
681            - wordpress 2.5.1-9 (embed; bug #443948)
682            - moodle <unfixed> (embed; bug #507185)
683            [etch] - phpgroupware <unfixed> (embed)
684            NOTE: phpgroupware-felamimail
685            - magpierss 0.72-3 (embed; bug #431089)
686    
687    jquery
688            - zekr <unfixed> (embed)
689            - wordpress <unfixed> (embed)
690            - yocto-reader <unfixed> (embed)
691            - textpattern <unfixed> (embed)
692            - genshi 0.5.1-1 (embed)
693            NOTE: compressed file under examples/ dir
694            - prewikka <unfixed> (embed)
695            - libramaze-ruby <unfixed> (embed)
696            - drupal5 <unfixed> (embed)
697            - b2evolution <unfixed> (embed)
698            - wesnoth <unfixed> (embed)
699    
700    tablesorter (jquery plugin, not packaged yet)
701            - wesnoth <unfixed> (embed)
702    
703    kses
704            - wordpress <unfixed> (embed; bug #504242)
705            NOTE: their copy has all methods renamed to wp_<foo>
706            - moodle <unfixed> (embed; bug #507185)
707            - egroupware <unfixed> (embed)
708    
709    magpierss
710            - wordpress <unfixed> (embed; bug #504242)
711            - moodle <unfixed>
712    
713    php-gettext
714            - wordpress <unfixed> (embed; bug #504242)
715    
716    libphp-ixr (name may change, it is the Incutio XML-RPC)
717            - wordpress <unfixed> (embed; bug #504242)
718            - dokuwiki <unfixed> (embed)
719            - textpattern <unfixed> (embed)
720    
721    libphp-cas
722            - glpi <unfixed> (embed)
723            - moodle <unfixed> (embed; bug #496069)
724    
725    scriptaculous
726            - glpi <unfixed> (embed)
727            - libaws <unfixed> (embed)
728            NOTE: libaws-doc
729            - op-panel <unfixed> (embed)
730            - symfony <unfixed> (embed)
731            NOTE: maintainer says there are extra incompatible changes required
732            - pixelpost <unfixed> (embed)
733            - webhelpers <unfixed> (embed)
734            NOTE: python-webhelpers
735            - qwik <unfixed> (embed)
736            - smokeping <unfixed> (embed)
737            - turba2 <unfixed> (embed)
738            - typo3-src 4.2.3-1 (embed)
739    
740    libmarkdown-php
741            - moodle <unfixed> (embed; bug #507185)
742            - pixelpost <unfixed> (embed)
743    
744    php-openid
745            - wordpress-openid <itp> (embed)
746    
747    geshi
748            - dokuwiki 0.0.20080505-3.1 (embed)
749            - pgfouine 1.0-1.1 (embed)
750            - websvn 2.1.0-1 (embed)
751    
752    webcalendar
753            - gforge-plugins-extra 4.7~rc2-6 (embed; bug #504758)
754    
755    libical
756            - kdepim <unfixed> (fork)
757            - kdepimlibs <unfixed> (fork)
758            NOTE: fixed in KDE4 post 4.1.x series
759    
760    libltdl3
761            - kdelibs <unfixed> (embed)
762            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
763            - synfig <unfixed> (embed)
764    
765    harfbuzz
766            - qt4-x11 <unfixed> (embed)
767    
768    libzip
769            - php5 <unfixed> (fork)
770    
771    json.php (not packaged; should be replaced with php's built-in functions)
772            - moodle <unfixed>
773            - yui <unfixed>
774            - gallery2 <unfixed>
775            - dokuwiki <unfixed>
776            - typo3-src <unfixed>
777    
778    php-fpdf
779            - tcpdf <itp> (fork)
780            - moodle <unfixed>
781            - phpwiki <unfixed>
782            - egroupware <unfixed>
783            - ldap-account-manager <unfixed> (fork)
784    
785    tcpdf (itp: #495985)
786            - moodle <unfixed>
787            - phpmyadmin <unfixed>
788    
789    typo3
790            - moodle <unfixed>
791    
792    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
793            - moodle <unfixed>
794            - gosa <unfixed>
795    
796    php-ole (itp: #487558)
797            - moodle <unfixed>
798    
799    pieforms (http://www.catalyst.net.nz)
800            - mahara <unfixed>
801    
802    savant2 (http://phpsavant.com)
803            - egroupware <unfixed>
804    
805    rssparser (http://nwow.org)
806            - egroupware <unfixed>
807            - phpgroupware <unfixed>
808    
809    lcms
810            - openjdk-6 <unfixed> (fork)
811    
812    libphp-phplayersmenu
813            - diogenes <unfixed>
814            - phpldapadmin <unfixed>
815    
816    libphp-pclzip
817            - docvert <unfixed>
818            - moodle <unfixed>
819            - egroupware <unfixed>
820    
821    libphp-simplepie
822            - dokuwiki <unfixed>
823    
824    libphp-jpgraph
825            - egroupware <unfixed>
826    
827    php-simpletest
828            - moodle <unfixed>
829    
830    libpng
831            - iceweasel <unfixed> (embed)
832            NOTE: 3.0 uses embedded copy, 2.0 uses system libpng
833            - icedove: 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
834            - iceape 1.0.13~pre080614i-0etch1 (embed)
835            - xulrunner <unfixed> (embed)
836            NOTE: Debian 1.9.0.6 uses embedded copy
837            NOTE: Ubuntu: 1.9.x use embedded copy, 1.8 and 1.8.1 use system libpng
838            - firefox 1.5.dfsg+1.5.0.3-0ubuntu3, 2.0.0.6+2nobinonly-0ubuntu1 (embed)
839            NOTE: Ubuntu only
840            - firefox-3.0 <unfixed> (embed)
841            NOTE: Ubuntu only
842            - firefox-3.1 <unfixed> (embed)
843            NOTE: Ubuntu only
844            - seamonkey 1.1.9+nobinonly-0ubuntu1 (embed)
845            NOTE: Ubuntu only
846            - thunderbird 2.0.0.6+nobinonly-0ubuntu1 (embed)
847            NOTE: Ubuntu only
848            - mozilla-thunderbird 1.5.0.2-0ubuntu2 (embed)
849            NOTE: Ubuntu only
850    
851    irssi
852            - silc-client <unfixed> (embed)
853            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
854    
855    extc
856            - mtasc <unfixed> (embed)
857            - haxe <unfixed> (embed)
858    
859    swflib
860            - mtasc <unfixed> (embed)
861            - haxe <unfixed> (embed)
862    
863  zlib code: (separate between 1.2 and 1.1)  libitext-java
864  dpkg          - bouncycastle 2.1.4-1 (embed)
 rsync  
 mozilla-firefox  
 mozilla(?)  
 Linux kernels  
865    
866    python-ply
867            - pyke <unfixed> (embed)
868    
869  libgadu/ekg:  libdumbnet (libdnet upstream)
870  centericq          - nmap <unfixed> (fork)
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not packaged in Debian)  
   
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki (not packaged in Debian)  
   
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 nvu  
   
   
 xli:  
 xloadimage  
   
   
 lesstif: (beware: two different lesstif APIs supported in one package, 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm, still the case with x.org?  
   
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum  
   
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 python  
 php4 (src included, but Debian package links dynamically)  
   
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
   
 uudeview:  
 libconvert-uulib-perl  
   
 sqlite: (not affected by security vulnerabilities so far)  
 amarok  

Legend:
Removed from v.1824  
changed lines
  Added in v.11863

  ViewVC Help
Powered by ViewVC 1.1.5