/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 1824 by jmm-guest, Tue Sep 6 07:54:13 2005 UTC revision 11923 by nion, Mon May 18 23:28:15 2009 UTC
# Line 1  Line 1 
1  This file collects cases, where a source package embeds code from  Embedded code copies
2  other projects, without linking dynamically:  ====================
3    
4  xpdf code: (some use xpdf 2, some xpdf 3)  This file collects source packages that embed code from other projects.
5  gpdf  This is considered bad for fixing security flaws because the fix needs
6  pdftohtml  to be applied in multiple source packages.
7  kdegraphics/kpdf  
8  tetex-bin  Format:
9  cupsys (only older releases, recent ones use xpdf-utils, it's still present in the src, though)  <srcpkg> (<optional comment about srcpkg>)
10  poppler          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11            NOTE: optional comments about the linkage of the embedding srcpkg
12    
13    status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp> or <unknown> if the version number can not be determined
15            <unfixable> for unavoidable cases (e.g., forks that add real value)
16    sort: static (linking statically against a lib)
17          embed (embedding a copy of the library into another source package)
18          fork (the package is not just embedding code but it is a fork and
19                thus might share parts of the source code)
20          old-version (the package is an older version of essentially
21                       the same code)
22    
23    The srcpkg might be some string to identify the code if there is no
24    specific source package.
25    
26    Everything up to the next line is ignored.
27    ---BEGIN
28    xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
29            NOTE: Fixed packages link to poppler library unless otherwise noted
30            - gpdf <removed>
31            [sarge] - gpdf <unfixed>
32            NOTE: has been replaced by evince in etch
33            - pdftohtml <unknown>
34            [sarge] - pdftohtml <unfixed>
35            [etch] - pdftohtml <unfixed>
36            NOTE: has been replaced by poppler-utils
37            - kdegraphics 4:4.2.2-1 (embed; bug #436164)
38            - texlive-base 3.0-12 (embed)
39            - texlive-bin 2007-1 (embed)
40            NOTE: links to poppler
41            - koffice <unfixed> (embed; bug #436163)
42            - libextractor 0.5.12-1 (embed)
43            NOTE: libextractor is using its own pdf decoder now
44            - pdfkit.framework 0.8-4 (embed)
45            - ipe <unfixed> (embed)
46            NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
47            - ruby-gnome2 <unknown> (embed)
48            NOTE: copy only present in source but links to poppler
49            - pdfedit <unfixed> (embed; bug #510794)
50            - swftools <unfixed> (embed)
51    
52    ppmd
53            - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)
54    
55    peercast
56            - gnome-peercast <unfixed> (embed)
57            NOTE: gnome-peercast may better be removed, see #466539
58    
59    silc-toolkit
60            - silc-client 1.1~beta6-1 (embed)
61    
62    icclib
63            - ghostscript <unfixed> (embed)
64            - argyll <unfixed> (embed)
65    
66    dietlibc
67            - ccontrol 0.9.1+20071204-1 (static)
68    
69    libmikmod
70            - sdl-mixer1.2 <unfixed> (embed)
71            TODO: report bug
72    
73    libiax
74            - iaxmodem <unfixed> (embed)
75    
76    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
77            - dpkg <unfixed> (embed)
78            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
79            - rsync <unfixed> (embed)
80            NOTE: somehow derived code base
81            - mono <unfixed> (embed)
82            TODO: check mozilla
83            - Linux kernels <unfixed> (embed)
84            - pvpgn 1.7.8-2 (embed)
85            - mrtg 2.12.2-1 (embed)
86            - rpm <unknown> (embed)
87            NOTE: pinged anibal since when rpm was fixed
88            - tuxcmd-modules <unfixed> (embed)
89            - zsync <unfixed>
90            - tra <unfixed>
91            - sash <unfixed>
92            - nsis <unfixed>
93            - mseide-msegui <unfixed>
94            NOTE: mseide
95            - mirrordir <unfixed>
96            - poco <unfixed>
97            - klibc <unfixed>
98            - ghostscript <unfixed>
99            - freeimage <unfixed>
100            - clamav <unfixed> (fork)
101            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
102            - tuxonice-userui <unfixed>
103            - plt-scheme <unfixed>
104            - perl <unfixed>
105            - paraview <unfixed>
106            - gcvs <unfixed>
107            - erlang <unfixed>
108            - dump <unfixed>
109            - aide <unfixed> (static)
110            - dar <unfixed> (static)
111            - avfs <unfixed>
112            - fpc <unfixed>
113            - winff <unfixed>
114            NOTE: inherited from fpc, see #472304
115            - lazarus <unfixed>
116            NOTE: inherited from fpc, see #472304
117    
118    libbz2
119            - dpkg <unfixed> (static)
120    
121    libgadu:
122            - centericq <unfixed> (embed)
123            - gaim <unfixed> (embed)
124            - pidgin <unfixed> (embed)(links dynamically against libgadu) (that should be fixed, then???)
125            - kdenetwork 4:3.3.2-5 (embed)
126            NOTE: from kdenetwork: kopete
127            - gadu <unfixed> (embed)
128            - ekg 1:1.8~rc0-1 (embed)
129            - kadu 0.6.0.2-3 (embed; bug #504430)
130            NOTE: gadu not packaged in Debian yet
131    
132    xmlrpc (which package is the "origin" of this code?)
133            - drupal <unfixed> (embed)
134            - phpgroupware <unfixed> (embed)
135            - egroupware <unfixed> (embed)
136            - phpwiki <unfixed> (embed)
137            - php4 <unfixed> (embed)
138            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
139    
140    shtool (affects build-time only)
141            - mysql-ocaml <unfixed> (embed)
142            - php4 <unfixed> (embed)
143    
144    mozilla source code
145            - mozilla-firefox <unfixed> (embed)
146            - mozilla-thunderbird <unfixed>
147            - firefox <removed>
148            - thunderbird <removed>
149            - iceweasel <unfixed> (embed)
150            - iceape <unfixed> (embed)
151            - icedove <unfixed> (embed)
152            - xulrunner <unfixed> (embed)
153            - nvu <removed> (embed)
154    
155    xli
156            - xloadimage <unfixed> (embed)
157    
158    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
159            - openmotif <unfixed> (embed)
160            - libxpm <unfixed> (embed)
161    
162    kerberized apps with BSD origin
163            - krb4 <unfixed> (embed)
164            - krb5 <unfixed> (embed)
165            - heimdal <unfixed> (embed)
166    
167    grip (which pkg is the origin?)
168            - libcdaudio <unfixed>
169            - grip <unfixed>
170            - gnome-vfs <unfixed>
171            TODO: check vfs2 as well
172    
173    fudforum
174            [etch] - phpgroupware <unfixed> (embed)
175            NOTE: phpgroupware-fudforum
176            [sarge] - egroupware-fudforum <removed> (embed)
177    
178    cvs
179            - gcvs <unfixed> (embed)
180            NOTE: see cvsunix/src in tarball
181    
182    pcre
183            - python* <unfixed> (embed)
184            - php4 <unknown> (embed)
185            - analog 2:5.23-0woody1 (embed)
186            - goffice <unfixed> (embed)
187            NOTE: libgoffice-*
188            - vfu 4.06-4.1 (embed; bug #450754)
189            - tf5 5.0beta7-1 (embed)
190            - monotone 0.43-1 (embed)
191            NOTE: this only affects versions >= 0.37
192            - glib2.0 2.15.2-1 (embed)
193            - apache2 2.0.53-4 (embed)
194            - exim4 4.10-0.srh20.12 (embed)
195            - yacas <unfixed> (embed)
196            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
197            - gtamsanalyzer.app 0.42-5 (embed)
198            - tin <unknown> (embed)
199            - kazehakase 0.5.2-1
200            - webkit <unfixed> (embed)
201            - qt4-x11 <unfixed> (embed)
202            NOTE: embedded via webkit copy
203    
204    tiff
205            - wxwindows2.4 2.2.1 (embed)
206    
207    uudeview
208            - libconvert-uulib-perl <unfixed> (embed)
209            - pan <unfixed> (embed)
210    
211    sqlite (not affected by security vulnerabilities so far)
212            - amarok <unfixed> (embed)
213            - monotone 0.43-1 (embed)
214            - iceweasel <unfixed> (embed)
215    
216    util-linux/mount
217            - loop-aes-utils <unfixed> (embed)
218            NOTE: contains code from util-linux' mount in the mount-aes-udeb
219    
220    webmin
221            - usermin <unknown> (embed)
222            [sarge] - usermin <unfixed> (embed)
223    
224    sylpheed
225            - sylpheed-claws <unfixed> (fork)
226    
227    phpsysinfo
228            - egroupware <unfixed> (embed)
229            - phpgroupware <unfixed> (embed)
230    
231    phpldapadmin
232            [sarge] - egroupware <unfixed> (embed)
233            NOTE: removed from egroupware after sarge
234    
235    chmlib
236            - kchmviewer <unknown> (embed)
237    
238    libavcodec/libavformat (source: ffmpeg)
239            - mplayer 1.0~rc2-14 (embed; bug #395252)
240            - kino 1.0.0-1
241            - vlc <not-affected> (Links dynamically since initial release)
242            - smilutils 0.3.0-10
243            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
244            - motion 3.1.19-1
245            - gstreamer0.10-ffmpeg 0.10.3-2
246            - xmovie <unfixed>
247            TODO: gimp-gap (potentially using ffmpeg code as well)
248    
249    faad2
250            - mplayer 1.0~rc2-20 (embed)
251    
252    mad MPEG decoding lib
253            - mad <unfixed> (embed)
254            - xine-lib <unfixed> (embed)
255    
256    libdts
257            - xine-lib <unfixed> (embed)
258    
259    flac
260            - xine-lib <unfixed> (embed)
261    
262    liba52
263            - a52dec <unfixed> (embed)
264            - xine-lib <unfixed> (embed)
265    
266    libmpeg2
267            - mpeg2dec <unfixed> (embed)
268            - xine-lib <unfixed> (embed)
269    
270    curl
271            - wget <unfixed> (embed)
272            NOTE: code for NTLM authentication
273    
274    uw-imap
275            - pine <unfixed> (embed)
276            - alpine <unfixed> (embed)
277    
278    imagemagick
279            - graphicsmagick <unfixed> (fork)
280    
281    halibut
282            - nsis <unfixed> (fork)
283    
284    libghttp
285            - hotway <unfixed> (embed)
286    
287    libsndfile
288            - ardour 1:2.7.1-1 (embed)
289    
290    glibmm2.4
291            - ardour 1:2.7.1-1 (embed)
292    
293    libgnomecanvasmm2.6
294            - ardour 1:2.7.1-1 (embed)
295    
296    libsigc++-2.0
297            - ardour 1:2.7.1-1 (embed)
298    
299    soundtouch
300            - ardour 1:2.7.1-1 (embed)
301    
302    libmms
303            - xine-lib <unfixed> (embed)
304            - mimms <unfixed> (embed)
305    
306    fckeditor
307            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
308            - moin 1.8.2-2 (embed; bug #452599)
309            - karrigell <removed> (embed; bug #452598)
310            - gforge 4.6.99+svn6225-1 (embed)
311    
312    ipatlas (not packaged in Debian)
313            - moodle <unfixed> (embed; bug #507185)
314    
315    libphp-phpmailer
316            - moodle <unfixed> (embed; bug #507185)
317            - mahara <unfixed> (embed)
318            - symfony <unfixed> (embed)
319            [etch] - phpgroupware <unfixed> (embed)
320            NOTE: phpgroupware-felamimail is only in etch
321            - egroupware <unfixed> (embed; bug #504283)
322            - glpi <unfixed>
323    
324    htmlArea (not packaged in Debian)
325            - moodle <unfixed> (embed)
326    
327    giflib:
328            - wine <unfixed> (embed; bug #466181)
329    
330    bennu (not packaged in Debian, http://bennu.sourceforge.net)
331            - moodle <unfixed> (embed)
332    
333    smarty:
334            - moodle 1.8.2-2 (embed; bug #471158)
335            - gallery2 2.2.5-2 (embed; bug #471160)
336            - mahara 0.9.2-2 (embed; bug #471201)
337            - gosa 2.4beta1-1 (embed; bug #471200)
338    
339    TinyMCE
340            - wordpress 2.5.1-3 (embed; bug #478257)
341            - moodle <unfixed> (embed; bug #507185)
342            - knowledgeroot <unfixed> (embed)
343            - joomla <itp> (bug #326398)
344    
345    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
346            - scite <unfixed> (embed)
347            - qscintilla <unfixed> (embed)
348            - qscintilla2 <unfixed> (embed)
349            - geany <unfixed> (fork)
350            - anjuta <unfixed> (embed)
351    
352    libphp-adodb
353            - moodle <unfixed> (embed; bug #507185)
354            NOTE: also AdoDB-XML Schema
355            - gallery2 <unfixed> (embed)
356            - phppgadmin <unfixed> (embed)
357            - egroupware <unfixed> (embed)
358            - phpwiki <unfixed> (embed)
359            - torrentflux 2.0beta1-2 (embed)
360            - ipplan <unfixed> (embed)
361            - typo3-src <unfixed> (embed)
362            - cacti <unknown> (embed)
363            [sarge] - cacti <unfixed> (embed)
364            NOTE: dependency exists, but internal version is used
365            - gforge 4.7~rc2-6 (embed)
366            - mahara <unfixed> (embed)
367    
368    gzip
369            - linux-kernel <unfixed> (embed)
370            NOTE: lib/inflate.c
371            - klibc <unfixed> (embed)
372            NOTE: based on linux-kernel gzip code
373            - busybox <unfixed> (embed)
374    
375    neon
376            - cadaver <unfixed> (embed; bug #188381)
377            - gnome-vfs2 <unfixed> (embed; bug #395874)
378            - litmus <unfixed> (embed; #395875)
379            [sarge] - screem <unfixed> (embed)
380            - sitecopy <unfixed> (embed; bug #395876)
381            [etch] - tla <unfixed> (embed; bug #395877)
382            [sarge] - tla <unfixed> (embed; bug #395877)
383    
384    libmodplug
385            - gst-plugins-bad0.10 <unfixed> (embed)
386    
387    libvncserver
388            - vino <unfixed> (embed)
389    
390    putty
391            - filezilla <unfixed> (embed)
392    
393    tinyxml (not packaged in Debian)
394            - filezilla <unfixed>
395    
396    gv
397            - evince <unfixed> (embed)
398            NOTE: ps/ tree from gv 3.5.8
399            - evince-gtk <unfixed> (embed)
400            NOTE: not packaged in Debian
401    
402    libXbae
403            [etch] - libpawlib2-lesstif <unfixed> (embed)
404            NOTE: from Cernlib
405    
406    libXaw
407            [etch] - libpawlib2-lesstif <unfixed>
408            NOTE: from Cernlib
409            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
410    
411    libgd2
412            - graphviz <unfixed> (embed)
413            NOTE: lib/gd seems to be 2.0.33
414            - wml <unfixed> (embed)
415            - libwmf <unfixed> (embed)
416            NOTE: derived from gd 1.6.3
417    
418    rar
419            - unrar-nonfree <unfixed> (embed)
420    
421    unrar-free (maybe this code is derived from the original rar, too?)
422            - clamav <unfixed> (embed)
423            NOTE: seems to be disabled in default config
424    
425    mplayer (DirectMedia Object loader)
426            - xine-lib <unfixed> (embed)
427            NOTE: src/libw32dll/
428            - vlc <unfixed> (embed)
429            NOTE: modules/codec/dmo/
430            - mplayer 1.0~rc2-20 (embed)
431    
432    libwpd (WordPerfect converter)
433            - openoffice.org <unfixed> (embed)
434    
435    fsplib (http://sourceforge.net/projects/fsp/)
436            - gftp <unfixed> (embed)
437            NOTE: lib/fsplib version 0.3
438    
439    sprng
440            - tree-puzzle <unfixed> (embed)
441    
442    librpcsecgss
443            - krb5 <unfixed> (embed)
444    
445    jasper
446            - ghostscript <unfixed> (embed)
447            - gs-gpl <unfixed> (embed)
448    
449    libiris
450            - psi <unfixed> (embed)
451            - kdenetwork <unfixed> (embed)
452            NOTE: kopete embeds libiris but links dynamically to libidn
453            - kdegames <unfixed> (embed)
454            NOTE: ksirk/kde4
455    
456    libidn
457            - monotone 0.43-1 (embed)
458            - psi <unfixed> (embed)
459            NOTE: psi embeds libiris which embeds libidn
460            - kdegames <unfixed> (embed)
461            NOTE: kdegames/kde4 embeds libiris which embeds libidn
462    
463    liblua
464            - monotone 0.43-1 (embed)
465            - nmap <unfixed> (embed; bug #527997)
466            NOTE: fixed upstream as of nmap svn rev13336.
467    
468    libbotan
469            - monotone 0.43-1 (embed)
470    
471    NetXX
472            - monotone 0.43-1 (embed)
473    
474    libgc
475            - mono <unfixed> (embed)
476    
477    lzma
478            - p7zip <unfixed> (embed)
479    
480    lzo
481            - grub2 <unfixed> (embed)
482    
483    yassl
484            - mysql-dfsg-5.0 <unfixed> (embed)
485    
486    pax code
487            - tar <unfixed> (embed)
488            - cpio <unfixed> (embed)
489    
490    t1lib
491            - tetex-bin 2.0.2-1 (embed)
492            - texlive-bin <unknown> (embed)
493    
494    guichan
495            - boswars <unfixed> (embed)
496            NOTE: maintainer notified us, working on it
497    
498    tolua
499            - boswars <unfixed> (embed)
500            NOTE: maintainer notified us, working on it
501    
502    asio-dev
503            - luxrender <unfixed> (embed)
504            NOTE: maintainer notified us, working on it
505            NOTE: may be merged with boost "soon"
506    
507    xine-lib
508            - vlc <unfixed> (embed)
509            NOTE: only parts included in modules/access/rtsp
510    
511    netpbm
512            - tcl8.3 <unfixed> (embed)
513            - tcl8.4 <unfixed> (embed)
514            - tcl8.5 <unfixed> (embed)
515            NOTE: generic/tkImgGIF.c
516    
517    tk8.5
518            - tk8.0 <removed> (old-version)
519            - tk8.3 <unfixed> (old-version)
520            - tk8.4 <unfixed> (old-version)
521            - perl-tk <unfixable> (fork)
522    
523    samba
524            - mc 2:4.6.2~git20080311-1 (embed)
525            NOTE: maintainer is aware of this, currently searching a solution
526    
527    plib1.8.4c2
528            - boson <unfixed> (fork)
529            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
530    
531    fribidi
532            - quesoglc <unfixed> (embed)
533            NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
534    
535    glew
536            - quesoglc <unfixed> (embed; bug #489341)
537            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
538    
539    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
540            - transcend <unfixed> (embed)
541            - cultivation <unfixed> (embed)
542            - passage <unfixed> (embed)
543            - gravitation <unfixed> (embed)
544    
545    tar
546            - libarchive <unfixed> (embed)
547            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
548    
549    cpio
550            - libarchive <unfixed> (embed)
551            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
552    
553    webkit
554            - qt4-x11 <unfixed> (embed)
555    
556    ftgl
557            - blender 2.46+dfsg-1 (embed)
558    
559    wv
560            - abiword <unfixed>
561    
562    qemu
563            - kvm <unfixed> (embed)
564            - xen-3 <unfixed> (embed)
565            - xen-unstable <unfixed> (embed)
566    
567    bochs
568            - kvm <unfixed> (embed; bug #489442)
569    
570    speex
571            - vorbis-tools <unfixed> (embed)
572            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
573            - gst-plugins-good0.10 <unfixed> (embed)
574            - xine-lib <unfixed> (embed)
575            - libfishsound <unfixed> (embed)
576            - libannodex <unfixed> (embed)
577            - vlc <unfixed> (embed)
578            - xmms-speex <unfixed> (embed)
579            - libsdl-sound1.2 <unfixed> (embed)
580            - sweep <unfixed> (embed)
581    
582    libreadline
583            - magic <unfixed> (old-version)
584            NOTE: magic is currently an RFS
585    
586    opcode
587            - ode <unfixed> (embed)
588            NOTE: opcode is not a package in debian, it is just embedded
589            NOTE: http://www.codercorner.com/Opcode.htm
590    
591    gimpact
592            - ode <unfixed> (embed)
593            NOTE: gimpact is not a package in debian, it is just embedded
594            NOTE: http://gimpact.sf.net
595    
596    mochikit
597            - mahara <unfixed> (embed)
598            NOTE: they require extra patches, still unmerged upstream
599            - ntop <unfixed> (embed)
600            - coherence <unfixed> (embed)
601            NOTE: python-coherence
602            - paste <unfixed> (embed)
603            NOTE: python-paste
604            - turbogears <unfixed> (embed)
605            NOTE: python-turbogears
606            - plone3 <unfixed> (embed)
607            NOTE: zope-plone3
608    
609    prototype
610            - netbeans-ide <unfixed> (embed)
611            - auth2db-frontend <unfixed> (embed)
612            - webcit <unfixed> (embed)
613            NOTE: citadel-webcit
614            - asterisk <unfixed> (embed)
615            - doc-iana <unfixed> (embed)
616            - libaws <unfixed> (embed)
617            NOTE: libaws-doc
618            - libgettext-ruby <unfixed> (embed)
619            NOTE: libgettext-ruby-data
620            - libjson-ruby <unfixed> (embed)
621            NOTE: libjson-ruby-doc
622            - lucene2 <unfixed> (embed)
623            NOTE: liblucene2-java-doc
624            - libopenid-ruby <unfixed> (embed)
625            - solr <unfixed> (embed)
626            NOTE: solr-common
627            - glpi <unfixed> (embed)
628            - hobbix <unfixed> (embed)
629            - mnemo2 <unfixed> (embed)
630            - nag2 <unfixed> (embed)
631            - knowledgeroot <unfixed> (embed)
632            - mediatomb <unfixed> (embed)
633            NOTE: mediatomb-common
634            - mt-daapd <unfixed> (embed)
635            - op-panel <unfixed> (embed)
636            - ebug-http <unfixed> (embed)
637            - phpgedview <removed> (embed)
638            - poker-network <unfixed> (embed)
639            NOTE: poker-web
640            - webhelpers <unfixed> (embed)
641            NOTE: python-webhelpers
642            - qwik <unfixed> (embed)
643            - rails <unfixed> (embed)
644            - typo3-src <unfixed> (embed)
645            - wordpress <unfixed> (embed)
646            - zope <unfixed> (embed)
647            NOTE: zope-plone3
648            - smokeping <unfixed> (embed)
649            - ampache 3.4.1-2 (embed)
650            - exaile <unfixed> (embed)
651            - hobix <unfixed> (embed)
652            - pixelpost <unfixed> (embed)
653            - symfony <unfixed> (embed)
654            NOTE: it's been said that there are custom changes
655            - zabbix <unfixed> (embed)
656            NOTE: zabbix-frontend-php
657            - turba2 <unfixed> (embed)
658    
659    gdb
660            - insight <unfixed> (embed)
661    
662    e2fsprogs
663            - ldiskfsprogs <unfixable> (fork)
664    
665    quazip (not packaged in Debian)
666            - qcake <unfixed> (embed)
667            NOTE: starting with upstream version 0.6.4
668    
669    exo
670            - pcmanfm <unfixed> (embed; bug #499677)
671            NOTE: slightly modified source code
672    
673    java
674            - openjdk-6 <unfixed>
675            - sun-java5 <unfixed>
676            - sun-java6 <unfixed>
677    
678    libphp-snoopy
679            - ampache 3.4.1-2 (embed; bug #504169)
680            - mahara 1.0.5-2 (embed; bug #504170)
681            - pixelpost <unfixed> (embed; bug #504171)
682            - mediamate 0.9.3.6-5 (embed; bug #504172)
683            - opendb <unfixed> (embed; bug #504173)
684            - wordpress 2.5.1-9 (embed; bug #443948)
685            - moodle <unfixed> (embed; bug #507185)
686            [etch] - phpgroupware <unfixed> (embed)
687            NOTE: phpgroupware-felamimail
688            - magpierss 0.72-3 (embed; bug #431089)
689    
690    jquery
691            - zekr <unfixed> (embed)
692            - wordpress <unfixed> (embed)
693            - yocto-reader <unfixed> (embed)
694            - textpattern <unfixed> (embed)
695            - genshi 0.5.1-1 (embed)
696            NOTE: compressed file under examples/ dir
697            - prewikka <unfixed> (embed)
698            - libramaze-ruby <unfixed> (embed)
699            - drupal5 <unfixed> (embed)
700            - b2evolution <unfixed> (embed)
701            - wesnoth <unfixed> (embed)
702    
703    tablesorter (jquery plugin, not packaged yet)
704            - wesnoth <unfixed> (embed)
705    
706    kses
707            - wordpress <unfixed> (embed; bug #504242)
708            NOTE: their copy has all methods renamed to wp_<foo>
709            - moodle <unfixed> (embed; bug #507185)
710            - egroupware <unfixed> (embed)
711    
712    magpierss
713            - wordpress <unfixed> (embed; bug #504242)
714            - moodle <unfixed>
715    
716    php-gettext
717            - wordpress <unfixed> (embed; bug #504242)
718    
719    libphp-ixr (name may change, it is the Incutio XML-RPC)
720            - wordpress <unfixed> (embed; bug #504242)
721            - dokuwiki <unfixed> (embed)
722            - textpattern <unfixed> (embed)
723    
724    libphp-cas
725            - glpi <unfixed> (embed)
726            - moodle <unfixed> (embed; bug #496069)
727    
728    scriptaculous
729            - glpi <unfixed> (embed)
730            - libaws <unfixed> (embed)
731            NOTE: libaws-doc
732            - op-panel <unfixed> (embed)
733            - symfony <unfixed> (embed)
734            NOTE: maintainer says there are extra incompatible changes required
735            - pixelpost <unfixed> (embed)
736            - webhelpers <unfixed> (embed)
737            NOTE: python-webhelpers
738            - qwik <unfixed> (embed)
739            - smokeping <unfixed> (embed)
740            - turba2 <unfixed> (embed)
741            - typo3-src 4.2.3-1 (embed)
742    
743    libmarkdown-php
744            - moodle <unfixed> (embed; bug #507185)
745            - pixelpost <unfixed> (embed)
746    
747    php-openid
748            - wordpress-openid <itp> (embed)
749    
750    geshi
751            - dokuwiki 0.0.20080505-3.1 (embed)
752            - pgfouine 1.0-1.1 (embed)
753            - websvn 2.1.0-1 (embed)
754    
755    webcalendar
756            - gforge-plugins-extra 4.7~rc2-6 (embed; bug #504758)
757    
758    libical
759            - kdepim <unfixed> (fork)
760            - kdepimlibs <unfixed> (fork)
761            NOTE: fixed in KDE4 post 4.1.x series
762    
763    libltdl3
764            - kdelibs <unfixed> (embed)
765            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
766            - synfig <unfixed> (embed)
767    
768    harfbuzz
769            - qt4-x11 <unfixed> (embed)
770    
771    libzip
772            - php5 <unfixed> (fork)
773    
774    json.php (not packaged; should be replaced with php's built-in functions)
775            - moodle <unfixed>
776            - yui <unfixed>
777            - gallery2 <unfixed>
778            - dokuwiki <unfixed>
779            - typo3-src <unfixed>
780    
781    php-fpdf
782            - tcpdf <itp> (fork)
783            - moodle <unfixed>
784            - phpwiki <unfixed>
785            - egroupware <unfixed>
786            - ldap-account-manager <unfixed> (fork)
787    
788    tcpdf (itp: #495985)
789            - moodle <unfixed>
790            - phpmyadmin <unfixed>
791    
792    typo3
793            - moodle <unfixed>
794    
795    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
796            - moodle <unfixed>
797            - gosa <unfixed>
798    
799    php-ole (itp: #487558)
800            - moodle <unfixed>
801    
802    pieforms (http://www.catalyst.net.nz)
803            - mahara <unfixed>
804    
805    savant2 (http://phpsavant.com)
806            - egroupware <unfixed>
807    
808    rssparser (http://nwow.org)
809            - egroupware <unfixed>
810            - phpgroupware <unfixed>
811    
812    lcms
813            - openjdk-6 <unfixed> (fork)
814    
815    libphp-phplayersmenu
816            - diogenes <unfixed>
817            - phpldapadmin <unfixed>
818    
819    libphp-pclzip
820            - docvert <unfixed>
821            - moodle <unfixed>
822            - egroupware <unfixed>
823    
824    libphp-simplepie
825            - dokuwiki <unfixed>
826    
827    libphp-jpgraph
828            - egroupware <unfixed>
829    
830    php-simpletest
831            - moodle <unfixed>
832    
833    libpng
834            - iceweasel <unfixed> (embed)
835            NOTE: 3.0 uses embedded copy, 2.0 uses system libpng
836            - icedove: 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
837            - iceape 1.0.13~pre080614i-0etch1 (embed)
838            - xulrunner <unfixed> (embed)
839            NOTE: Debian 1.9.0.6 uses embedded copy
840            NOTE: Ubuntu: 1.9.x use embedded copy, 1.8 and 1.8.1 use system libpng
841            - firefox 1.5.dfsg+1.5.0.3-0ubuntu3, 2.0.0.6+2nobinonly-0ubuntu1 (embed)
842            NOTE: Ubuntu only
843            - firefox-3.0 <unfixed> (embed)
844            NOTE: Ubuntu only
845            - firefox-3.1 <unfixed> (embed)
846            NOTE: Ubuntu only
847            - seamonkey 1.1.9+nobinonly-0ubuntu1 (embed)
848            NOTE: Ubuntu only
849            - thunderbird 2.0.0.6+nobinonly-0ubuntu1 (embed)
850            NOTE: Ubuntu only
851            - mozilla-thunderbird 1.5.0.2-0ubuntu2 (embed)
852            NOTE: Ubuntu only
853    
854    irssi
855            - silc-client <unfixed> (embed)
856            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
857    
858    extc
859            - mtasc <unfixed> (embed)
860            - haxe <unfixed> (embed)
861    
862    swflib
863            - mtasc <unfixed> (embed)
864            - haxe <unfixed> (embed)
865    
866  zlib code: (separate between 1.2 and 1.1)  libitext-java
867  dpkg          - bouncycastle 2.1.4-1 (embed)
 rsync  
 mozilla-firefox  
 mozilla(?)  
 Linux kernels  
868    
869    python-ply
870            - pyke <unfixed> (embed)
871    
872  libgadu/ekg:  libdumbnet (libdnet upstream)
873  centericq          - nmap <unfixed> (fork)
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not packaged in Debian)  
   
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki (not packaged in Debian)  
   
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 nvu  
   
   
 xli:  
 xloadimage  
   
   
 lesstif: (beware: two different lesstif APIs supported in one package, 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm, still the case with x.org?  
   
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum  
   
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 python  
 php4 (src included, but Debian package links dynamically)  
   
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
   
 uudeview:  
 libconvert-uulib-perl  
   
 sqlite: (not affected by security vulnerabilities so far)  
 amarok  

Legend:
Removed from v.1824  
changed lines
  Added in v.11923

  ViewVC Help
Powered by ViewVC 1.1.5