/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 4827 by micah, Fri Oct 6 19:38:03 2006 UTC revision 15492 by silvio-guest, Thu Oct 21 05:29:40 2010 UTC
# Line 1  Line 1 
1    Embedded code copies
2    ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects, without linking dynamically:  This is considered bad for fixing security flaws because the fix needs
6    to be applied in multiple source packages.
7  xpdf code: (some use xpdf 2, some xpdf 3)  
8  gpdf (will be replaced by evince in Gnome 2.12)  Format:
9  pdftohtml (current poppler source package has a ported version, pinged maintainer)  <srcpkg> (<optional comment about srcpkg>)
10  kdegraphics/kpdf (upstream is working on using poppler, probably not in time for Etch)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11  tetex-bin (links to poppler since 3.0-12)          NOTE: optional comments about the linkage of the embedding srcpkg
12  cupsys (only older releases, recent ones use xpdf-utils, it's still present in the src, though)  
13  poppler  status: version number fixing the embedded copy
14  koffice (upstream is working on using poppler, probably not in time for Etch)          <unfixed> if the issue is not yet fixed
15  libextractor (uses internal pdf decoder since 0.5.12-1)          <removed> if the package was removed from the archive
16  pdfkit.framework (links to poppler since 0.8-4)          <itp> if the package is in the process of being packaged
17            <not-affected> if the package does not use the embedded copy
18  zlib code: (lots of apps embed a copy, but link dynamically, but there are a few exceptions)          <unknown> if the version number can not be determined
19  dpkg          <unfixable> for unavoidable cases (e.g., forks that add real value)
20  rsync (somehow derived code base)  sort: static (linking statically against a lib)
21  mozilla(?)        embed (embeds a copy of the library into another source package)
22  Linux kernels        modified-embed (embeds a code copy that differs from upstream code)
23  pvpgn (links dynamically since 1.7.8-2)        fork (a full-blown fork of another source package)
24  mrtg (links dynamically since 2.12.2-1)        old-version (an older version of essentially the same code)
   
 libgadu/ekg:  
 centericq  
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not yet packaged in Debian)  
   
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki (not packaged in Debian)  
   
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 nvu  
   
   
 xli:  
 xloadimage  
   
   
 lesstif: (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm)  
   
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum  
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 all pythons  
 php4 (src included, but Debian package links dynamically)  
 analog (src included, but Debian package links dynamically)  
 libgoffice-1  
 tf5 (since 5.0beta7 the Debian package links dynamically)  
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
25    
26    The srcpkg might be some string to identify the code if there is no
27    specific source package.
28    
29  uudeview:  Everything up to the next line is ignored.
30  libconvert-uulib-perl  ---BEGIN
31    poppler
32  sqlite: (not affected by security vulnerabilities so far)          - pdftohtml <unknown>
33  amarok          [sarge] - pdftohtml <unfixed>
34            [etch] - pdftohtml <unfixed>
35  util-linux/mount:          NOTE: has been replaced by poppler-utils
36  loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
37            - texlive-base 3.0-12 (embed)
38  webmin:          - texlive-bin 2007-1 (embed)
39  usermin          - koffice 1:2.0.0-1 (embed; bug #436163)
40            - libextractor 0.5.12-1 (embed)
41  sylpheed:          NOTE: libextractor is using its own pdf decoder now
42  sylpheed-claws          - ipe <unfixed> (embed)
43            NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44  phpsysinfo:          - ruby-gnome2 <unknown> (embed)
45  egroupware          - pdfedit <unfixed> (embed; bug #510794)
46  phpgroupware          - swftools <removed> (embed; bug #551293)
47            - xpdf 3.02-9 (fork)
48  phpldapadmin:  
49  egroupware  pdksh (no longer developed since 1999)
50            - mksh <unfixable> (fork)
51  chmlib:          - posh <unfixable> (fork)
52  kchmviewer (not packaged in Debian)  
53    ppmd
54  libavcodec/libavformat:          - libcomplearn-mod-ppmd <unfixed> (fork)
55  ffmpeg          NOTE: discussion in #458152
56  xine-lib  
57  xvidcap (currently in NEW)  libevent
58  kino (links statically, does not include code)          - transmission 1.71-1 (embed; bug #529372)
59  vlc (links statically, does not include code)          - chromium-browser 5.0.375.29~r46008-1
60  smilutils (links statically, does not include code)          - dnsproxy <unknown> (embed)
61  motion (links statically, does not include code)  
62  gst-ffmpeg  lrmi
63  xmovie (currently in NEW)          - read-edid 2.0.0-1 (embed; bug #495131)
64  gst-ffmpeg          - s3switch <unfixed> (embed)
65            - xresprobe <unfixed> (embed)
66  mad MPEG decoding lib:          - zhcon <unfixed> (embed)
67  mad  
68  xine-lib  php-htmlpurifier
69            - mahara 1.2.5-1 (embed)
70            - knowledgeroot 0.9.9.5-5 (embed)
71            - moodle <unfixed> (embed)
72    
73    peercast
74            - gnome-peercast <removed> (embed)
75            [etch] - gnome-peercast <unfixed> (embed)
76    
77    silc-toolkit
78            - silc-client 1.1~beta6-1 (embed)
79    
80    icclib
81            - ghostscript <unfixed> (embed)
82            - argyll <unfixed> (embed)
83    
84    libusb
85            - argyll <unfixed> (embed)
86    
87    dietlibc
88            - ccontrol 0.9.1+20071204-1 (static)
89            - mksh <unfixable> (static)
90            NOTE: /bin/mksh-static only, and only on some arches (others use eglibc)
91    
92    libmikmod
93            - sdl-mixer1.2 <unfixed> (embed)
94            TODO: report bug
95    
96    libiax
97            - iaxmodem <unfixable> (embed; bug #548885)
98    
99    spandsp
100            - iaxmodem <unfixable> (embed; bug #548885)
101    
102    python-paramiko
103            - fabric 0.9.0-2 (embed; bug #561398)
104    
105    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
106            - dpkg 1.15.6 (static)
107            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
108            - rsync <unfixed> (embed)
109            - cherokee <unfixed> (embed)
110            NOTE: somehow derived code base
111            - mono <unfixed> (embed)
112            TODO: check mozilla
113            - Linux kernels <unfixed> (embed)
114            - pvpgn 1.7.8-2 (embed)
115            - mrtg 2.12.2-1 (embed)
116            - rpm <unknown> (embed)
117            NOTE: pinged anibal since when rpm was fixed
118            - tuxcmd-modules <unfixed> (embed)
119            - zsync <unfixed>
120            - tra <unfixed>
121            - sash <unfixed>
122            - nsis <unfixed>
123            - pyfits 1:2.3.1-1
124            - mseide-msegui <unfixed>
125            NOTE: mseide
126            - mirrordir <unfixed>
127            - poco <unfixed>
128            - klibc <unfixed>
129            - emboss <unfixed>
130            - ghostscript <unfixed>
131            - freeimage <unfixed>
132            - clamav <unfixed> (fork)
133            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
134            - tuxonice-userui <unfixed> (static)
135            - plt-scheme <unfixed>
136            - perl <unfixed>
137            - paraview <unfixed>
138            - velvet 0.7.56~nozlibcopy-1
139            - gcvs <unfixed>
140            - dump <unfixed>
141            - aide <unfixed> (static)
142            - dar <unfixed> (static)
143            - avfs <unfixed>
144            - fpc <unfixed>
145            - winff <unfixed>
146            NOTE: inherited from fpc, see #472304
147            - lazarus <unfixed>
148            NOTE: inherited from fpc, see #472304
149            - erlang <unfixed> (embed)
150            - gamera 3.2.3-1 (embed)
151            - python2.4 <unfixed> (embed; bug #553403)
152            - python2.5 <unfixed> (embed; bug #553403)
153            - texlive-bin <unknown> (embed)
154    
155    dulwich
156            - hg-git 0.1.0-1 (embed; bug #541996)
157    
158    libvigraimpex
159            - hugin <unfixed> (embed; bug #542259)
160            - enblend-enfuse <unfixed> (embed; bug #542258)
161            - gamera 3.2.3-1 (embed)
162    
163    libbz2
164            - dpkg 1.15.6 (static)
165            - amd64-libs <unfixed> (static)
166            NOTE: let's call it "static"
167            - dar <unfixed> (static)
168            - dump <unfixed> (static)
169            - unalz 0.64-1 (embed)
170            NOTE: has code, by the maint, to use the system version but links against the internal copy
171            - clamav <unfixed> (embed)
172            NOTE: libclamav/nsis/bzlib*
173            - pristine-tar <unfixable> (modified-embed)
174            NOTE: compression code only, not uncompression
175            - r-base-core-ra 1.2.8 (static)
176            - r-base-core 2.11.1 (static)
177            NOTE: links dynamically in squeeze, statically in lenny
178            - rpm <unfixed> (static)
179            NOTE: lsb-rpm package is statically linked, normal rpm links dynamically
180    
181    libyahoo2
182            - centerim <unfixed> (embed; bug #559783)
183    
184    libmsn
185            - centerim <unfixed> (embed; bug #559783)
186    
187    libgadu
188            - centerim <unfixed> (embed; bug #559783)
189            - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
190            - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
191            - kdenetwork 4:3.3.2-5 (embed)
192            NOTE: from kdenetwork: kopete
193            - ekg 1:1.8~rc0-1 (embed)
194            - kadu 0.6.0.2-3 (embed; bug #504430)
195            - gadu <itp> (embed)
196    
197    xmlrpc (which package is the "origin" of this code?)
198            - drupal <unfixed> (embed)
199            - phpgroupware <unfixed> (embed)
200            - egroupware <unfixed> (embed)
201            - phpwiki <unfixed> (embed)
202            - php4 <removed> (embed)
203            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
204    
205    shtool (affects build-time only)
206            - mysql-ocaml <unfixed> (embed)
207            - php4 <removed> (embed)
208            - php5 <unfixed> (embed)
209    
210    xulrunner
211            - iceape <unfixed> (embed; bug #561749)
212            - iceweasel 2.0.0.19 (embed)
213            - icedove <unfixed> (embed; bug #561750)
214            - kompozer <unfixed> (embed; bug #532168)
215            - galeon 2.0.2-4 (embed)
216            - epiphany-browser 2.14.3-8 (embed)
217            - conkeror 0.9~git080629-2 (embed)
218            - kazehakase 0.4.2-1 (embed)
219    
220    xli
221            - xloadimage <unfixed> (embed)
222    
223    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
224            - openmotif <unfixed> (embed)
225    
226    libxpm
227            - lesstif2 <unfixed> (embed; bug #575750)
228    
229    kerberized apps with BSD origin
230            - krb4 <removed> (embed)
231            - krb5 <unfixed> (embed)
232            - heimdal <unfixed> (embed)
233    
234    grip (which pkg is the origin?)
235            - libcdaudio <unfixed>
236            - grip <unfixed>
237            - gnome-vfs <unfixed>
238            TODO: check vfs2 as well
239    
240    fudforum
241            [etch] - phpgroupware <unfixed> (embed)
242            NOTE: phpgroupware-fudforum
243            [sarge] - egroupware-fudforum <removed> (embed)
244    
245    libbsd
246            - rdate 1:1.2-3 (embed)
247            - atheme-services <unfixed>
248            - libbsd-arc4random-perl <not-affected> (modified-embed)
249            NOTE: code not used, it links dynamically against libbsd instead
250            - isakmpd <unfixed>
251            - bsdgames <unfixed> (embed)
252            - bsd-mailx <unfixed> (embed)
253            - netcat-openbsd <unfixed> (embed; bug #550611)
254            - openssh <unfixed> (embed)
255            - unworkable <unfixed> (embed)
256            - mksh <unfixed> (modified-embed)
257            NOTE: strlcpy(), only used in /bin/mksh-static on eglibc arches
258            NOTE: FIXME, we should only have one entry: - mksh <not-affected> (modified-embed)
259            NOTE: strlcpy() on dietlibc arches; {g,s}etmode(); both unused
260    
261    cvs
262            - gcvs <unfixed> (embed)
263            NOTE: see cvsunix/src in tarball
264    
265    pcre3
266            - php4 <removed> (embed)
267            - analog 2:5.23-0woody1 (embed)
268            - goffice <unfixed> (embed)
269            NOTE: libgoffice-*
270            - vfu 4.06-4.1 (embed; bug #450754)
271            - tf5 5.0beta7-1 (embed)
272            - monotone 0.43-1 (embed)
273            NOTE: this only affects versions >= 0.37
274            - glib2.0 2.15.2-1 (embed)
275            - apache2 2.0.53-4 (embed)
276            - exim4 4.10-0.srh20.12 (embed)
277            - yacas <unfixed> (embed)
278            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
279            - gtamsanalyzer.app 0.42-5 (embed)
280            - tin 980117-1 (embed)
281            - kazehakase 0.5.2-1
282            - webkit 1.0.1-1 (embed)
283            - qt4-x11 <unfixed> (embed)
284            NOTE: embedded via webkit copy
285            - erlang <unfixed> (embed)
286            - ssed <unfixed> (embed)
287            - ircd-hybrid <unfixed> (static)
288            - emboss <unfixd>
289            - cherokee <unfixed> (embed)
290            - oftc-hybrid 1.6.9.dfsg-1 (embed)
291            - ratbox-services <unfixed> (embed)
292            - squeak-vm <unfixed> (embed)
293            - tinymux <unfixed> (embed)
294    
295    tiff
296            - wxwindows2.4 2.2.1 (embed)
297            - gamera 3.2.3-1 (embed)
298            - freeimage <unfixed> (embed)
299            - libtk-img <unfixed> (embed)
300            NOTE: there are two copies, one under tiff/ other under libtiff/
301            - gdal <unfixed>
302    
303    uudeview
304            - libconvert-uulib-perl <unfixed> (embed)
305            - pan <unfixed> (embed)
306    
307    sqlite (not affected by security vulnerabilities so far)
308            - amarok <unfixed> (embed)
309            - monotone 0.43-1 (embed)
310            - iceweasel <unfixed> (embed)
311            - heimdal <unfixed> (embed; bug #559616)
312    
313    util-linux/mount
314            - loop-aes-utils <unfixed> (embed)
315            NOTE: contains code from util-linux' mount in the mount-aes-udeb
316    
317    sylpheed
318            - sylpheed-claws <unfixed> (fork)
319    
320    phpsysinfo
321            - egroupware <unfixed> (embed)
322            - phpgroupware <unfixed> (embed)
323    
324    phpldapadmin
325            [sarge] - egroupware <unfixed> (embed)
326            NOTE: removed from egroupware after sarge
327    
328    chmlib
329            - kchmviewer <unknown> (embed)
330    
331    ffmpeg (libavcodec/libavformat)
332            - mplayer 1.0~rc2-14 (embed; bug #395252)
333            - kino 1.0.0-1
334            - vlc <not-affected> (Links dynamically since initial release)
335            - smilutils 0.3.0-10
336            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
337            - motion 3.1.19-1
338            - gstreamer0.10-ffmpeg 0.10.3-2
339            - xmovie <removed> (static)
340            TODO: gimp-gap (potentially using ffmpeg code as well)
341            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
342            - audacity 1.3.7-2 (embed; bug #512278)
343            - chromium-browser <unfixed> (fork)
344    
345    faad2
346            - mplayer 1.0~rc2-20 (embed)
347            - avifile <unfixed> (embed; bug #538750)
348            - ffmpeg-debian <removed> (embed)
349    
350    libmad (MPEG decoding lib)
351            - xine-lib <unfixed> (embed)
352            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
353            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
354    
 libdts:  
355  libdts  libdts
356  xine-lib          - xine-lib <unfixed> (embed)
357    
 flac:  
358  flac  flac
359  xine-lib          - xine-lib <unfixed> (embed)
360    
361  liba52:  liba52
362  a52dec          - a52dec <unfixed> (embed)
363  xine-lib          - xine-lib <unfixed> (embed)
364    
365  libmpeg2:  mpeg2dec (libmpeg2)
366  mpeg2dec          - xine-lib <unfixed> (embed)
367  xine-lib  
368    libmpeg3
369            - squeak-vm <unfixed> (embed)
370    
371    libntlm
372            - wget <unfixed> (fork; bug #550436)
373            - curl <unfixed> (fork; bug #550437)
374            - cntlm <unfixed> (fork; bug #550438)
375    
376    uw-imap
377            - pine <unfixed> (embed)
378            - alpine <unfixed> (embed)
379    
380    imagemagick
381            - graphicsmagick <unfixed> (fork)
382    
383    python-urlgrabber
384            - mercurial <unfixed> (embed; bug #531062)
385            - w3af <unfixed> (embed; bug #555372)
386            [experimental] - harvestman <unfixed> (embed; bug #555373)
387    
388    beautifulsoup
389            - python-mechanize <unfixed> (embed; bug #555349)
390            - zope2.11 <removed> (embed; bug #555350)
391            - twill <unknown> (embed)
392    
393    halibut
394            - nsis <unfixed> (fork)
395    
396    libghttp
397            - hotway <unfixed> (embed)
398    
399    libsndfile
400            - ardour 1:2.7.1-1 (embed)
401    
402    glibmm2.4
403            - ardour 1:2.7.1-1 (embed)
404    
405    libgnomecanvasmm2.6
406            - ardour 1:2.7.1-1 (embed)
407    
408    libsigc++-2.0
409            - ardour 1:2.7.1-1 (embed)
410    
411    soundtouch
412            - ardour 1:2.7.1-1 (embed)
413    
414    libmms
415            - xine-lib <unfixed> (embed)
416            - mimms <unfixed> (embed)
417    
418    fckeditor
419            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
420            - moin 1.8.2-2 (embed; bug #452599)
421            - karrigell <removed> (embed; bug #452598)
422            - gforge 4.6.99+svn6225-1 (embed)
423            - request-tracker3.8 <unfixed> (embed)
424            - otrs2 <unfixed> (embed)
425    
426    ipatlas (not packaged in Debian)
427            - moodle <unfixed> (embed; bug #507185)
428    
429    libphp-phpmailer
430            - moodle <unfixed> (embed; bug #507185)
431            - mahara <unfixed> (embed)
432            - symfony <unfixed> (embed; bug #566778)
433            [etch] - phpgroupware <unfixed> (embed)
434            NOTE: phpgroupware-felamimail is only in etch
435            - egroupware <unfixed> (embed; bug #504283)
436            - glpi <unfixed>
437    
438    htmlArea (not packaged in Debian)
439            - moodle <unfixed> (embed)
440    
441    giflib
442            - wine <unfixed> (embed; bug #466181)
443    
444    bennu (not packaged in Debian, http://bennu.sourceforge.net)
445            - moodle <unfixed> (embed)
446    
447    smarty
448            - moodle 1.8.2-2 (embed; bug #471158)
449            - gallery2 2.2.5-2 (embed; bug #471160)
450            - mahara 0.9.2-2 (embed; bug #471201)
451            - gosa 2.4beta1-1 (embed; bug #471200)
452    
453    TinyMCE
454            - wordpress 2.5.1-3 (embed; bug #478257)
455            - moodle <unfixed> (embed; bug #507185)
456            - knowledgeroot <unfixed> (embed)
457            - joomla <itp> (bug #326398)
458            - mahara 1.2.6-1 (embed; #597752)
459    
460    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
461            - scite <unfixed> (embed)
462            - qscintilla <unfixed> (embed)
463            - qscintilla2 <unfixed> (embed)
464            - geany <unfixed> (fork)
465            - anjuta <unfixed> (embed)
466    
467    libphp-adodb
468            - moodle <unfixed> (embed; bug #507185)
469            NOTE: also AdoDB-XML Schema
470            - gallery2 <unfixed> (embed)
471            - phppgadmin <unfixed> (embed)
472            - egroupware <unfixed> (embed)
473            - phpwiki <unfixed> (embed)
474            - torrentflux 2.0beta1-2 (embed)
475            - ipplan <unfixed> (embed)
476            - typo3-src <unfixed> (embed)
477            - cacti <unknown> (embed)
478            [sarge] - cacti <unfixed> (embed)
479            NOTE: dependency exists, but internal version is used
480            - gforge 4.7~rc2-6 (embed)
481            - mahara <unfixed> (embed)
482    
483    gzip
484            - linux-2.6 <unfixed> (embed) [lib/inflate.c]
485            - klibc <unfixed> (embed)
486            NOTE: based on linux-kernel gzip code
487            - busybox <unfixed> (embed)
488            - pristine-tar <unfixed> (modified-embed)
489            NOTE: compression code only, not uncompression
490            - ncompress <unfixed> (old-version)
491    
492    neon
493            - cadaver 0.22.3+debian-1 (embed; bug #188381)
494            - gnome-vfs2 <unfixed> (embed; bug #395874)
495            [etch] - litmus <unfixed> (embed; #395875)
496            - litmus <removed> (embed; #395875)
497            [sarge] - screem <unfixed> (embed)
498            - sitecopy 1:0.16.0-1 (embed; bug #395876)
499            [etch] - tla <unfixed> (embed; bug #395877)
500            [sarge] - tla <unfixed> (embed; bug #395877)
501    
502    libmodplug
503            - gst-plugins-bad0.10 0.10.10.2-1 (embed)
504    
505    libvncserver
506            - vino <unfixed> (embed)
507    
508    putty
509            - filezilla <unfixed> (embed)
510    
511    tinyxml (not packaged in Debian; itp bug #531968)
512            - filezilla <unfixed>
513            - crystalspace <unfixed> (embed)
514            - libwfut <unfixed> (embed)
515            - rarian <unfixed> (embed)
516            - bulletml <unfixed> (embed)
517            - pokerth <unfixed> (embed)
518            - qutecom <unfixed> (embed)
519            - sofa-framework <unfixed> (embed)
520            - yate <unfixed> (embed)
521            - antigrav <unfixed> (embed)
522            - balder2d <unfixed> (embed)
523            - cal3d <unfixed> (embed)
524            - criticalmass <unfixed> (embed)
525            - ember <unfixed> (embed)
526            - epiphany <unfixed> (embed)
527            - gambit <unfixed> (embed)
528            - noiz2sa <unfixed> (embed)
529            - ogre <unfixed> (embed)
530            - opencity <unfixed> (embed)
531            - openmovieeditor <unfixed> (embed)
532            - pouetchess <unfixed> (embed)
533            - tecnoballz <unfixed> (embed)
534            - trigger-rally <unfixed> (embed)
535            - xmoto <unfixed> (embed)
536            - mapnik <unknown> (embed)
537            NOTE: uses a different XML parser by default
538            - rrootage 0.23a-6 <embed>
539            NOTE: links to libbulltetml
540            - boson <unknown> (embed)
541            NOTE: the embedded code is unused
542    
543    gv
544            - evince <unfixed> (embed)
545            NOTE: ps/ tree from gv 3.5.8
546            NOTE: evince-gtk is affected (a component of evince source package)
547    
548    libXbae
549            - paw <unfixed> (embed)
550    
551    libgtkhtml
552            - claws-mail-extra-plugins <unfixed> (fork)
553    
554    libXaw
555            - paw <unfixed> (embed)
556            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
557    
558    libgd2
559            - graphviz <unfixed> (embed)
560            NOTE: lib/gd seems to be 2.0.33
561            - wml 2.0.11ds2-1 (embed)
562            - libwmf <unfixed> (embed)
563            NOTE: derived from gd 1.6.3
564            - texlive-bin 2009-1 (embed)
565    
566    rar
567            - unrar-nonfree <unfixed> (embed)
568    
569    unrar-free (maybe this code is derived from the original rar, too?)
570            - clamav <unfixed> (embed)
571            NOTE: seems to be disabled in default config
572    
573    mplayer (DirectMedia Object loader)
574            - xine-lib <unfixed> (embed)
575            NOTE: src/libw32dll/
576            - vlc <unfixed> (embed)
577            NOTE: modules/codec/dmo/
578            - mplayer 1.0~rc2-20 (embed)
579    
580    libwpd (WordPerfect converter)
581            - openoffice.org <unfixed> (embed)
582    
583    fsplib (http://sourceforge.net/projects/fsp/)
584            - gftp <unfixed> (embed)
585            NOTE: lib/fsplib version 0.3
586    
587    sprng
588            - tree-puzzle <unfixed> (embed)
589    
590    librpcsecgss
591            - krb5 <unfixed> (embed)
592    
593    jasper
594            - ghostscript 8.64~dfsg-2 (embed)
595    
596    libiris
597            - psi <unfixed> (embed)
598            - kdenetwork <unfixed> (embed)
599            NOTE: kopete embeds libiris but links dynamically to libidn
600            - kdegames <unfixed> (embed)
601            NOTE: ksirk/kde4
602    
603    libidn
604            - monotone 0.43-1 (embed)
605            - psi <unfixed> (embed)
606            NOTE: psi embeds libiris which embeds libidn
607            - kdegames <unfixed> (embed)
608            NOTE: kdegames/kde4 embeds libiris which embeds libidn
609    
610    lua5.1
611            - monotone 0.43-1 (embed)
612            - nmap 5.00-1 (embed; bug #527997)
613            [lenny] - nmap <unfixed> (embed; bug #527997)
614            - ocropus <unfixed> (embed)
615            - enigma <unfixed> (embed)
616            NOTE: requires lua built with C++
617            - freeciv <unfixed> (embed)
618            - spring <unfixed> (embed)
619    
620    libbotan
621            - monotone 0.43-1 (embed)
622    
623    NetXX
624            - monotone 0.43-1 (embed)
625    
626    libgc
627            - mono <unfixed> (embed)
628    
629    lzma
630            - p7zip <unfixed> (embed)
631            - xz-utils <unfixed> (fork)
632            - r-base <unfixed> (embed)
633            NOTE: lzma support not yet in lenny or in r-base-core-ra 1.2.8
634    
635    lzo
636            - grub2 <unfixed> (embed)
637    
638    yassl
639            - mysql-dfsg-5.0 <unfixed> (embed)
640            - mysql-5.1 <unfixed> (embed)
641    
642    pax code
643            - tar <unfixed> (embed)
644            - cpio <unfixed> (embed)
645    
646    t1lib
647            - tetex-bin 2.0.2-1 (embed)
648            - texlive-bin <unknown> (embed)
649    
650    guichan
651            - boswars <unfixed> (embed)
652            NOTE: maintainer notified us, working on it
653    
654    tolua
655            - boswars <unfixed> (embed)
656            NOTE: maintainer notified us, working on it
657            NOTE: actually tolua++
658            - ocropus <unfixed> (embed)
659            NOTE: actually tolua++
660            - freeciv <unfixed> (embed)
661            NOTE: actually tolua++
662            - enigma <unfixed> (embed)
663    
664  curl:  asio-dev
665  wget (code for NTLM authentication)          - luxrender <removed> (embed)
666    
667  TODO evaluate:  xine-lib
668  gimp-gap (potentially using ffmpeg code as well)          - vlc <unfixed> (embed)
669            NOTE: only parts included in modules/access/rtsp
670    
671  uw-imap:  netpbm
672  pine          - tcl8.3 <unfixed> (embed)
673            - tcl8.4 <unfixed> (embed)
674            - tcl8.5 <unfixed> (embed)
675            NOTE: generic/tkImgGIF.c
676    
677    tk8.5
678            - tk8.0 <removed> (old-version)
679            - tk8.3 <unfixed> (old-version)
680            - tk8.4 <unfixed> (old-version)
681            - perl-tk <unfixable> (fork)
682    
683    samba
684            - mc 2:4.6.2~git20080311-1 (embed)
685            NOTE: maintainer is aware of this, currently searching a solution
686    
687    plib1.8.4c2
688            - boson <unfixed> (fork)
689            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
690    
691    fribidi
692            - quesoglc 0.7.2-2 (embed)
693    
694    glew
695            - quesoglc <unfixed> (embed; bug #489341)
696            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
697            - trigger 0.5.2.1-2 (embed)
698            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
699            - trigger-rally 0.5.2.1-2 (embed)
700            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
701            - chromium-browser 5.0.375.70~r48679-2
702    
703    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
704            - transcend <unfixed> (embed)
705            - cultivation <unfixed> (embed)
706            - passage <unfixed> (embed)
707            - gravitation <unfixed> (embed)
708    
709    tar
710            - libarchive <unfixed> (embed)
711            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
712    
713    cpio
714            - libarchive <unfixed> (embed)
715            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
716    
717    kde4libs
718            - kdelibs <unfixable> (old-version)
719    
720    webkit
721            - qt4-x11 <unfixed> (embed; bug #479851)
722            [etch] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
723            - kde4libs <unfixable> (fork)
724            NOTE: kde4lib's khtml and webkit were forked from khtml (this tracking, which seems
725            NOTE: reversed genesis-wise, is used because of so much other stuff in kde4libs)
726            - chromium-browser <unfixed> (fork)
727    
728    ftgl
729            - blender 2.46+dfsg-1 (embed)
730    
731    wv
732            - abiword <unfixed>
733    
734    qemu
735            - kvm <removed> (embed; bug #543159)
736            - qemu-kvm <unfixed> (embed; bug #560853)
737            NOTE: kvm superceded by qemu-kvm, which is just user interface (no modules)
738            - xen-3 3.4.2-2 (embed; bug #560856)
739            - xen-unstable <unfixed> (embed; bug #560856)
740    
741    vgabios
742            - kvm <removed> (embed; bug #489442)
743            - qemu-kvm <unfixed> (embed)
744    
745    bochs
746            - kvm <removed> (embed; bug #489442)
747            - qemu-kvm <unfixed> (embed)
748    
749    speex
750            - vorbis-tools <unfixed> (embed)
751            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
752            - gst-plugins-good0.10 <unfixed> (embed)
753            - xine-lib <unfixed> (embed)
754            - libfishsound <unfixed> (embed)
755            - libannodex <removed> (embed)
756            - vlc <unfixed> (embed)
757            - xmms-speex <unfixed> (embed)
758            - libsdl-sound1.2 <unfixed> (embed)
759            - sweep <unfixed> (embed)
760    
761    libreadline
762            - magic <itp> (old-version)
763    
764    opcode
765            - ode <unfixed> (embed)
766            NOTE: opcode is not a package in debian, it is just embedded
767            NOTE: http://www.codercorner.com/Opcode.htm
768    
769    gimpact
770            - ode <unfixed> (embed)
771            NOTE: gimpact is not a package in debian, it is just embedded
772            NOTE: http://gimpact.sf.net
773    
774    mochikit
775            - mahara <unfixed> (embed)
776            NOTE: they require extra patches, still unmerged upstream
777            - ntop <unfixed> (embed)
778            - coherence 0.6.2-1 (embed)
779            - paste <unfixed> (embed)
780            - turbogears <unfixed> (embed)
781            - plone3 <removed> (embed)
782            - xulrunner <unfixed> (embed)
783            - libjifty-plugin-chart-perl <unfixed> (embed)
784            - sabnzbdplus <unfixed> (embed)
785            - tgmochikit <unfixed> (embed)
786    
787    prototypejs
788            - netbeans-ide 6.0.1+dfsg-2 (embed)
789            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
790            - webcit <unfixed> (embed; bug #555219)
791            - asterisk 1:1.6.2.0~rc3-1 (embed)
792            - libjson-ruby 1.1.4-1 (embed; bug #555224)
793            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
794            - horde3 <unfixed> (embed)
795            - knowledgeroot 0.9.8.5-4 (embed; bug #555230)
796            - mediatomb 0.12.0~svn2018-5 (embed; bug #555233)
797            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
798            - ebug-http <unfixed> (embed; bug #555236)
799            - libaws 2.7-1 (embed; bug #555222)
800            - phpgedview <removed> (embed)
801            - poker-network 1.7.6-1 (embed; bug #555238)
802            - rails 2.1.0-6 (embed)
803            - wordpress 2.5.0-2 (embed; bug #555243)
804            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
805            TODO: search through all of the other zope packages
806            - ampache 3.4.1-2 (embed)
807            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
808            - hobix 0.5~svn20070319-4 (embed; bug #555247)
809            - zabbix 1.6.6-4 (embed; bug #555250)
810            - chora2 2.1.1+debian0-1 (embed; bug #555253)
811            - gollem 1.1.1+debian0-1 (embed; bug # 555254)
812            - jscropperui 1.2.1-1 (embed; bug #555257)
813            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
814            - ingo1 1.2.3+debian0-1 (embed; bug #555261)
815            - kronolith2 2.3.3+debian0-1 (embed; bug #555262)
816            - activeldap 1.2.1-1 (embed)
817            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
818            - mantis 1.1.2+dfsg-1 (embed; bug #555265)
819            - otrs2 2.3.4-6 (embed; bug #555267)
820            - webcalendar 1.2~b1-2 (embed; bug #555269)
821            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
822            - jifty 0.90519-1 (embed; bug #555271)
823            - jquery 1.4-1 (embed; bug #555272)
824            - passenger 2.2.5debian1-1 (embed; bug #555273)
825            - plone3 <removed> (embed; bug #555275)
826            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
827            - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
828            - xulrunner <unfixed> (embed)
829            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
830            - jclicmoodle <unfixed> (embed)
831            - git-cola <unfixed> (embed)
832    
833    gdb
834            - insight <unfixed> (embed)
835    
836    e2fsprogs
837            - ldiskfsprogs <unfixable> (fork)
838    
839    quazip (not packaged in Debian)
840            - qcake <unfixed> (embed)
841            NOTE: starting with upstream version 0.6.4
842    
843    exo
844            - pcmanfm <unfixed> (embed; bug #499677)
845            NOTE: slightly modified source code
846    
847    java
848            - openjdk-6 <unfixed>
849            - sun-java5 <unfixed>
850            - sun-java6 <unfixed>
851    
852    libphp-snoopy
853            - ampache 3.4.1-2 (embed; bug #504169)
854            - gforge 4.6.99+svn6094-2 (embed)
855            - mahara 1.0.5-2 (embed; bug #504170)
856            - pixelpost 1.7.1-5 (embed; bug #504171)
857            - mediamate 0.9.3.6-5 (embed; bug #504172)
858            - opendb <removed> (embed; bug #504173)
859            [etch] - opendb <unfixed> (embed; bug #504173)
860            - wordpress 2.5.1-9 (embed; bug #443948)
861            - moodle <unfixed> (embed; bug #507185)
862            [etch] - phpgroupware <unfixed> (embed)
863            NOTE: phpgroupware-felamimail
864            - magpierss 0.72-3 (embed; bug #431089)
865    
866    jquery
867            - zekr <unfixed> (embed)
868            - wordpress <unknown> (embed)
869            - yocto-reader <unfixed> (embed)
870            - textpattern <unfixed> (embed)
871            - genshi 0.5.1-1 (embed)
872            NOTE: compressed file under examples/ dir
873            - prewikka <unfixed> (embed)
874            - libramaze-ruby <unfixed> (embed)
875            - drupal6 <unfixed> (embed)
876            - b2evolution <unfixed> (embed)
877            - wesnoth <unfixed> (embed)
878    
879    tablesorter (jquery plugin, not packaged yet)
880            - wesnoth <unfixed> (embed)
881    
882    kses
883            - wordpress <unfixed> (embed; bug #504242)
884            NOTE: their copy has all methods renamed to wp_<foo>
885            NOTE: kses isn't in Debian, RFP: #504240
886            - moodle <unfixed> (embed; bug #507185)
887            - egroupware <unfixed> (embed)
888    
889    magpierss
890            - wordpress <unfixed> (embed; bug #504242)
891            - moodle <unfixed>
892    
893    php-gettext
894            - wordpress 2.8.4-1 (embed; bug #504242)
895            - docbookwiki <unfixed> (embed)
896            - knowledgeroot 0.9.9.5-1
897            NOTE: non-free
898    
899    libphp-ixr (name may change, it is the Incutio XML-RPC)
900            - wordpress <unfixed> (embed; bug #504242)
901            NOTE: libphp-ixr isn't in Debian, RFP: #504236
902            - dokuwiki <unfixed> (embed)
903            - textpattern <unfixed> (embed)
904    
905    libphp-cas
906            - glpi <unfixed> (embed)
907            - moodle <unfixed> (embed; bug #505984)
908    
909    scriptaculous (prototype.js is among the embeds in the following)
910            - glpi <unfixed> (embed)
911            - libaws <unfixed> (embed; bug #555222)
912            - op-panel <unfixed> (embed)
913            - symfony <unfixed> (embed)
914            NOTE: maintainer says there are extra incompatible changes required
915            - pixelpost 1.7.1-6 (embed)
916            - webhelpers <unfixed> (embed)
917            - qwik <removed> (embed; bug #555241)
918            - smokeping <unfixed> (embed)
919            - turba2 <unfixed> (embed)
920            - typo3-src 4.2.3-1 (embed)
921            - request-tracker3.6 <unfixed> (embed)
922            - request-tracker3.8 <unfixed> (embed)
923            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
924            - wordpress 2.5.0-2 (embed)
925            - libhtml-prototype-perl 1.48-3 (embed)
926    
927    libmarkdown-php
928            - moodle <unfixed> (embed; bug #507185)
929            - pixelpost 1.7.1-6 (embed)
930    
931    php-openid
932            - wordpress-openid 3.3.2-1 (embed)
933    
934    geshi
935            - dokuwiki 0.0.20080505-3.1 (embed)
936            - pgfouine 1.0-1.1 (embed)
937            - websvn 2.1.0-1 (embed)
938    
939    webcalendar
940            - gforge 4.7~rc2-6 (embed; bug #504758)
941    
942    libical
943            - kdepim <unknown> (fork)
944            NOTE: fixed at some point during 4.0
945            - kdepimlibs 4.2.0-1 (fork)
946            - claws-mail-extra-plugins <unfixed> (fork)
947    
948    harfbuzz
949            - qt4-x11 <unfixed> (embed)
950            - pango1.0 <unfixed> (embed)
951            - fontmatrix <unfixed> (embed)
952    
953    libzip
954            - php5 <unfixable> (modified-embed)
955            - odt2txt <unfixed> (embed; bug #523808)
956    
957    json.php (not packaged; should be replaced with php's built-in functions)
958            - moodle <unfixed>
959            - yui <unfixed>
960            - gallery2 <unfixed>
961            - dokuwiki <unfixed>
962            - typo3-src <unfixed>
963    
964    php-fpdf
965            - tcpdf <itp> (fork)
966            - moodle <unfixed>
967            - phpwiki <unfixed>
968            - egroupware <unfixed>
969            - ldap-account-manager <unfixed> (fork)
970    
971    tcpdf (itp: #495985)
972            - moodle <unfixed>
973            - phpmyadmin <unfixed>
974    
975    typo3
976            - moodle <unfixed>
977    
978    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
979            - moodle <unfixed>
980            - gosa <unfixed>
981    
982    php-ole (itp: #487558)
983            - moodle <unfixed>
984    
985    pieforms (http://www.catalyst.net.nz)
986            - mahara <unfixed>
987    
988    savant2 (http://phpsavant.com)
989            - egroupware <unfixed>
990    
991    rssparser (http://nwow.org)
992            - egroupware <unfixed>
993            - phpgroupware <unfixed>
994    
995    lcms
996            - openjdk-6 <unfixed> (fork)
997            - gimp 2.4.0~rc2-2
998    
999    libphp-phplayersmenu
1000            - diogenes <unfixed>
1001            - phpldapadmin <unfixed>
1002    
1003    libphp-pclzip
1004            - docvert <unfixed>
1005            - moodle <unfixed>
1006            - egroupware <unfixed>
1007    
1008    libphp-simplepie
1009            - dokuwiki <unfixed>
1010            - wordpress <unfixed>
1011    
1012    libphp-jpgraph
1013            - egroupware <unfixed>
1014    
1015    php-simpletest
1016            - moodle <unfixed>
1017    
1018    libpng
1019            - iceweasel <not-affected> (uses xulrunner)
1020            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
1021            - iceape 1.0.13~pre080614i-0etch1 (embed)
1022            - xulrunner 1.9.0.13-1 (embed)
1023            [lenny] - xulrunner 1.9.0.11-0lenny1
1024            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1025            - gamera 3.2.3-1 (embed)
1026            - freeimage <unfixed> (embed)
1027            - tuxonice-userui <unfixed> (static)
1028    
1029    irssi
1030            - silc-client <unfixed> (embed)
1031            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
1032    
1033    extc
1034            - mtasc <unfixed> (embed)
1035            - haxe <unfixed> (embed)
1036    
1037    swflib
1038            - mtasc <unfixed> (embed)
1039            - haxe <unfixed> (embed)
1040    
1041    libitext-java
1042            - bouncycastle 2.1.4-1 (embed)
1043    
1044    python-ply
1045            - pyke <unfixed> (embed; bug #555363)
1046            - pywbem 0.7.0-4 (embed; bug #555364)
1047            - sepolgen <unfixed> (embed; bug #555365)
1048            - zope-textindexng3 <unknown> (embed)
1049            - iceweasel <not-affected> (uses xulrunner)
1050            - xulrunner <unknown> (embed)
1051            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
1052    
1053    libdumbnet (libdnet upstream)
1054            - nmap <unfixed> (fork)
1055    
1056    gcc-4.4
1057            - gcc-mingw32 <unfixed> (embed)
1058    
1059    camlimages
1060            - advi <unfixed> (static; bug #550441)
1061    
1062    memcached
1063            - memcachedb <unfixed> (embed)
1064    
1065    yajl
1066            - argyll <unfixed> (embed; bug #544223)
1067            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
1068    
1069    nusoap
1070            - gforge 4.8.2-1 (embed)
1071            - ampache <unfixed> (embed)
1072            - poker-network <unfixed> (embed)
1073            - moodle <unfixed> (embed)
1074            NOTE: code is not used when running under php5 and soap is enabled
1075            - phpwiki <unfixed> (embed)
1076            - gallery2 <unfixed> (embed)
1077            - typo3-src <unfixed> (embed)
1078            - phpgacl 3.3.7-7 (embed)
1079            - mantis 1.1.8+dfsg-1 (embed)
1080    
1081    libept
1082            - adept <unfixed> (embed; bug #540649)
1083    
1084    libvorbis
1085            - iceweasel <not-affected> (uses xulrunner)
1086            - xulrunner <unfixed> (embed; bug #540959)
1087            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1088            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1089            - iceape <unfixed> (embed)
1090            [etch] - iceape <not-affected> (introduced in 2.0)
1091            [lenny] - iceape <not-affected> (introduced in 2.0)
1092    
1093    cairo
1094            - iceweasel <not-affected> (uses xulrunner)
1095            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1096    
1097    liboggz
1098            - iceweasel <not-affected> (uses xulrunner)
1099            - xulrunner <unfixed> (embed; bug #540959)
1100            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1101            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1102            - iceape <unfixed> (embed)
1103            [etch] - iceape <not-affected> (introduced in 2.0)
1104            [lenny] - iceape <not-affected> (introduced in 2.0)
1105    
1106    liboggplay
1107            - iceweasel <not-affected> (uses xulrunner)
1108            - xulrunner <unfixed> (embed; bug #540959)
1109            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1110            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1111            - iceape <unfixed> (embed)
1112            [etch] - iceape <not-affected> (introduced in 2.0)
1113            [lenny] - iceape <not-affected> (introduced in 2.0)
1114    
1115    php-net-dnsbl
1116            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1117    
1118    php-onyx-rss
1119            - serendipity <unfixed> (embed; bug #541740; wontfix: only one script, own package is overkill, appears not to be duplicated in Debian)
1120    
1121    php-text-wiki
1122            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1123    
1124    php-xml-rpc
1125            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1126    
1127    polarssl (does not have a shared library)
1128            - pdkim <itp> (embed; bug #543150)
1129            - xyssl <unfixed> (old-version)
1130    
1131    pidgin (libpurple)
1132            - gaim <removed> (old-version)
1133            - qutecom 2.2~rc3.hg396~dfsg1-6 (embed; bug #559785)
1134    
1135    icu
1136            - webkit 1.0.1-1 (embed; bug #547214)
1137            - texlive-bin <unfixed> (fork)
1138            NOTE: texlive upstream working with icu upstream to merge their changes
1139            - chromium-browser 5.0.375.29~r46008-3
1140    
1141    cyrus-imapd-2.2
1142            - kolab-cyrus-imapd <unfixed> (fork)
1143            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1144    
1145    python-cxx-dev
1146            - freecad 0.9.2646.3-1 (embed; bug #547936)
1147    
1148    zipios++
1149            - freecad 0.9.2646.3-1 (embed; bug #547941)
1150            - enigma 0.92.3-3 (embed)
1151            NOTE: likely fixed earlier, marking etch's version as fixed
1152    
1153    linux-2.6
1154            - kvm <removed> (embed; bug #549973) [./kernel/*]
1155            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1156            - kernel-source-2.6.8 <removed> (old-version)
1157            - kernel-source-2.4.27 <removed> (old-version)
1158            - kernel-source-2.4.24 <removed> (old-version)
1159            - kernel-source-2.2.25 <removed> (old-version)
1160            - kernel-source-2.2.20 <removed> (old-version)
1161    
1162    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1163            - kvm <removed> (embed) [./libfdt/*]
1164            - qemu-kvm <unfixed> (embed) [./libfdt/*]
1165    
1166    qweb (not packaged)
1167            - ajaxterm <unfixed>
1168    
1169    opensaml2
1170            - opensaml <removed> (old-version)
1171    
1172    shibboleth-sp2
1173            - shibboleth-sp <removed> (old-version)
1174    
1175    tuxonice-userui
1176            - suspend2-userui <removed> (old-version)
1177    
1178    expat
1179            - w3c-libwww <removed> (embed; bug #551941)
1180            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1181            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1182            - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1183            - python2.4 <unfixable> (embed; bug #553403)
1184            - python2.7 2.7-6 (embed)
1185            - python-4suite <unfixed> (embed; bug #516935)
1186            - wxwindows2.4 <removed> (embed)
1187            - wxwidgets2.6 2.6.3.2.2-4 (embed)
1188            - wxwidgets2.8 2.8.10.1-2 (embed)
1189            - celementtree 1.0.5-8 (embed)
1190            NOTE: Maybe that was fixed even earlier
1191            - audacity 1.3.2-1 (embed)
1192            - matanza <unfixed> (embed)
1193            - tdom 0.8.3~20080525-1 (embed)
1194            - udunits 2.1.8-4 (embed)
1195            - apr-util 1.2 (embed)
1196            - ayttm <unfxed> (embed; bug #561006)
1197            - cableswig <unfixed> (embed)
1198            - cadaver <unfixed> (embed)
1199            - cmake 2.6.0-6 (embed)
1200            - coin3 <unfixed> (embed)
1201            - gdcm 2.0.14-2 (embed)
1202            - ghostscript 8.71~dfsg-2 (embed)
1203            - grmonitor <removed> (embed)
1204            - iceape <unfixed> (embed)
1205            - insighttoolkit 3.16.0-1 (embed)
1206            NOTE: insighttoolkit might've been fixed earlier
1207            - libparagui1.1 1.0.2-1 (embed)
1208            - paraview 3.6.2-1 (embed)
1209            - poco 1.3.6p1-1 (embed)
1210            - simgear <unfixed> (embed)
1211            - sitecopy 1:0.16.0-1
1212            - smart <unfixed> (embed)
1213            NOTE: smart embeds celementree, and it includes expat
1214            - swish-e <not-affected> (Linked against libxml, which is used instead)
1215            - tla 1.3.5+dfsg-15 (embed)
1216            - vtk 4.1.20030227-1 (embed)
1217            - wbxml2 <not-affected> (expat code is only used on Mac OS X, see #560941)
1218            - xmlrpc-c <unfixed> (embed)
1219            - iceweasel <unfixed> (embed)
1220            - kompozer <unfixed> (embed)
1221            - vxl 1.13.0-2 (embed)
1222            - xulrunner <unfixed> (embed)
1223            - apache2 2.2 (embed)
1224            - texlive-bin <not-affected> (Embedded code not compiled in)
1225            - vnc4 <unfixed> (embed)
1226            - xotcl 1.6.6-1 (embed)
1227            - chromium-browser 5.0.375.29~r46008-3
1228    
1229    xerces-c
1230            - xerces-c2 <unfixed> (old-version)
1231            - xerces27 <removed> (old-version)
1232    
1233    md5 (RSA's version; not the gnu version provided by coreutils)
1234            - w3c-libwww <removed> (embed; bug #551942)
1235            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1236    
1237    libparagui1.1
1238            - asc <unfixable> (fork)
1239    
1240    enet
1241            - sauerbraten <unfixed> (embed; #497194)
1242    
1243    eglibc
1244            - glibc <removed> (old-version)
1245            - mksh <unfixable> (static)
1246              NOTE: /bin/mksh-static only, and only on some arches (others use dietlibc)
1247    
1248    galib
1249            - gamera 3.2.3-1 (embed)
1250    
1251    configobj
1252            - bzr 2.1.0~rc2-1 (embed; bug #555336)
1253            - elisa <unfixed> (embed; bug #555337)
1254            - gaupol <unfixed> (embed; bug #555338)
1255            - ipython <unfixed> (embed; bug #555339)
1256            - pida <unfixed> (embed; bug #555340)
1257            - psychopy <unfixed> (embed; bug #555341)
1258            - rest2web <unfixed> (embed; bug #555342)
1259            - auth2db <unknown> (embed)
1260            - dynagen <unknown> (embed)
1261            - iceweasel <unknown> (embed)
1262            - sabnzbdplus <unknown> (embed)
1263            - xulrunner <unknown> (embed)
1264            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1265    
1266    python-clientform
1267            - bibus <unfixed> (embed; bug #555332)
1268            - zope2.10 <unfixed> (embed; bug #555333)
1269            - zope2.11 <removed> (embed; bug #555334)
1270            - python-mechanize <unknown> (embed)
1271            - twill <unknown> (embed)
1272    
1273    python-mechanize
1274            - zope2.10 <unfixed> (embed; bug #555337)
1275            - zope2.11 <removed> (embed; bug #555338)
1276            - twill <unknown> (embed; bug #555339)
1277    
1278    pexpect
1279            - duplicity 0.6.06-1 (embed; bug #555361)
1280            - hplip <unfixed> (embed; bug #555362)
1281            - smart <unfixed> (embed; bug #555363)
1282    
1283    pyparsing
1284            - bauble <unfixed> (embed; bug #555366)
1285            - boa-constructor 0.6.1-8 (embed; bug #555367)
1286            - calibre <unfixed> (embed; bug #555368)
1287            - matplotlib <unfixed> (embed; bug #531024)
1288            - zhpy 1.7.3.1-1 (embed; bug #555370)
1289            - polybori <unknown> (embed)
1290            - python-whoosh <unknown> (embed)
1291            - twill <unknown> (embed)
1292            - zope-textindexng3 <unknown> (embed)
1293    
1294    python-pysqlite2
1295            - python2.4 <unfixed> (embed; bug #553403)
1296            - python2.5 <unfixed> (embed; bug #553403)
1297    
1298    celementtree
1299            - python2.5 <unfixed> (embed)
1300            - smart <unfixed> (embed)
1301    
1302    elementtree
1303            - python2.5 <unfixed> (embed)
1304            - python2.6 <unfixed> (embed)
1305            - bzr 2.1.0~rc2-1 (embed; bug #555343)
1306            - gedit 2.28.2-1 (embed; bug #555344)
1307            - smart <unfixed> (embed)
1308            - solfege <unfixed> (embed; bug #555345)
1309            - w3af <unfixed> (embed; bug #555346)
1310            - python-qt4 <unknown> (embed)
1311            - sphinx <unknown> (embed)
1312            - python-nltk <itp> (embed)
1313    
1314    python2.5
1315            - python2.4 <unfixed> (old-version)
1316            - jython <unfixed> (embed)
1317            NOTE: embeds many stdlib modules
1318            - python-django <unfixed> (embed; bug #555419)
1319            NOTE: embeds stdlib modules: doctest, decimal
1320            - gamera 3.2.3-1 (embed)
1321            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1322            - boa-constructor <unfixed> (embed; bug #555426)
1323            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1324            - nicotine <unfixed> (embed; bug #555427)
1325            NOTE: embeds stdlib modules: ConfigParser
1326            - museek+ <unfixed> (embed; bug #555428)
1327            NOTE: embeds stdlib modules: ConfigParser
1328            - vegastrike-data <removed> (embed)
1329            NOTE: embeds many stdlib modules
1330            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1331            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1332            - config-manager <unfixed> (embed; bug #555423)
1333            NOTE: embeds stdlib modules: optparse
1334            - jhbuild 2.28.0-1 (embed; bug #555421)
1335            NOTE: embeds stdlib modules: optparse, subprocess
1336            - smart <unfixed> (embed; bug #555432)
1337            NOTE: embeds stdlib modules: optparse
1338            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1339            NOTE: embeds stdlib modules: doctest
1340            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1341            NOTE: embeds stdlib modules: doctest
1342            - distribute <unfixed> (embed)
1343            NOTE: embeds stdlib modules: doctest
1344            - python-setuptools <unfixed> (embed; bug #555435)
1345            NOTE: embeds stdlib modules: doctest
1346            - zope.testing <unfixed> (embed; bug #555436)
1347            NOTE: embeds stdlib modules: doctest
1348            - translate-toolkit <unfixed> (embed; bug #555422)
1349            NOTE: embeds stdlib modules: textwrap, contextlib
1350            - libtpclient-py <unfixed> (embed; bug #555424)
1351            NOTE: embeds stdlib modules: subprocess
1352            - grass <unfixed> (embed; bug #555425)
1353            NOTE: embeds stdlib modules: subprocess
1354            - coherence <unfixed> (embed; bug #555429)
1355            NOTE: embeds stdlib modules: uuid
1356            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1357            NOTE: embeds stdlib modules: uuid
1358            - setroubleshoot <removed> (embed; bug #555431)
1359            NOTE: embeds stdlib modules: uuid
1360            - linkchecker <unfixed> (embed; bug #555414)
1361            NOTE: embeds msgfmt.py script
1362            - imdbpy <unfixed> (embed)
1363            NOTE: embeds msgfmt.py script
1364            - kiwi <unfixed> (embed)
1365            NOTE: embeds msgfmt.py script
1366            - moin <unfixed> (embed)
1367            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1368            - plone3 <removed> (embed)
1369            NOTE: embeds msgfmt.py script
1370            - roundup <unfixed> (embed)
1371            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1372            - rednotebook <unfixed> (embed; bug #555415)
1373            NOTE: embeds msgfmt.py script
1374            - turbogears <unfixed> (embed)
1375            NOTE: embeds msgfmt.py script
1376            - elisa <unfixed> (embed)
1377            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1378            - calibre <unfixed> (embed)
1379            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1380            - mailman 1:2.1.13-1 (embed; #555416)
1381            NOTE: embeds msgfmt.py script
1382            - python-docutils <unknown> (embed)
1383            NOTE: embeds stdlib modules: optparse, textwrap
1384            - python-imaging <unknown> (embed)
1385            NOTE: embeds stdlib modules: doctest
1386            - python-mechanize <unknown> (embed)
1387            NOTE: embeds stdlib modules: doctest
1388            - twill <unknown> (embed)
1389            NOTE: embeds stdlib modules: subprocess
1390            - zeroc-ice <unknown> (embed)
1391            NOTE: embeds stdlib modules: subprocess
1392            - wxwidgets2.8 <unknown> (embed)
1393            NOTE: embeds stdlib modules: subprocess
1394            - cycle <unknown> (embed)
1395            NOTE: embeds msgfmt.py script
1396            - deluge <unknown> (embed)
1397            NOTE: embeds msgfmt.py script
1398            - opendict <unknown> (embed)
1399            NOTE: embeds msgfmt.py script
1400            - openerp-client <unknown> (embed)
1401            NOTE: embeds msgfmt.py script
1402            - rapidsvn <unknown> (embed)
1403            NOTE: embeds msgfmt.py script
1404            - wammu <unknown> (embed)
1405            NOTE: embeds msgfmt.py script
1406            - gaphor <unknown> (embed)
1407            NOTE: embeds msgfmt.py script
1408            - pida <unknown> (embed)
1409            NOTE: embeds msgfmt.py script
1410            - python-formencode <unknown> (embed)
1411            NOTE: embeds msgfmt.py script
1412            - duplicity <unfixed> (embed)
1413            NOTE: embeds stdlib module: urlparse, tarfile
1414            - pygopherd <unfixed> (embed)
1415            NOTE: embeds stdlib module: zipfile
1416    
1417    argparse
1418            - twill <unfixed> (embed; bug #555347)
1419            - ipython <unfixed> (embed; bug #555348)
1420    
1421    coherence
1422            - elisa <unfixed> (embed; bug #555335)
1423    
1424    simpletal
1425            - plastex <unfixed> (embed; bug #555371)
1426    
1427    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1428            - postr <unfixed> (embed)
1429            - elisa <unfixed> (embed)
1430    
1431    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1432            - apertium-tolk <unfixed> (embed)
1433            - ipython <unfixed> (embed)
1434            - virtaal <unfixed> (embed)
1435    
1436    distribute
1437            - setuptools <removed> (old-version)
1438    
1439    rails
1440            - jruby1.2 <removed> (embed) [./bench/rails/*]
1441            NOTE: jruby is in non-free, it probably includes rails too
1442            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1443            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1444            - thin <unfixed> (embed) [./spec/rails_app/*]
1445            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1446            NOTE: be dangerous if developers are naively basing their code off of the examples
1447            NOTE: prototype.js is among the example files
1448    
1449    lucene2 (prototype.js is among the embeds in the following)
1450            - lucene <unfixed> (old-version)
1451            - pylucene <unfixed> (embed)
1452            - libpdfbox-java <unfixed> (embed)
1453            - libfontbox-java <unfixed> (embed)
1454            - libjempbox-java <unfixed> (embed)
1455            - solr <unfixed> (embed)
1456    
1457    unicode-data
1458            - syslinux <unfixed> (embed)
1459            - camomile <unfixed> (embed)
1460            - fribidi <unfixed> (embed)
1461            - m17n-db <unfixed> (embed)
1462            - sbcl <unfixed> (embed)
1463            - heimdal <unfixed> (embed)
1464            - icu <unfixed> (embed)
1465            - icu4j <unfixed> (embed)
1466            - krb5 <unfixed> (embed)
1467            - moodle <unfixed> (embed)
1468            - openldap <unfixed> (embed)
1469            - pike7.6 <unfixed> (embed)
1470            - samba <unfixed> (embed)
1471            - samba4 <unfixed> (embed)
1472            - cmucl <unfixed> (embed)
1473            - typo3-src <unfixed> (embed)
1474            - mauve <unfixed> (embed)
1475            - texlive-bin <unfixed> (embed)
1476            - ypsilon <unfixed> (embed)
1477            - jeuclid <unfixed> (embed)
1478            - charmap.app <unfixed> (embed)
1479            - clisp <unfixed> (embed)
1480            - gnulib <unfixed> (embed)
1481            - opensrs-client <unfixed> (embed)
1482            - saxonb <unfixed> (embed)
1483            - rails <unfixed> (embed)
1484    
1485    feedparser
1486            - rawdog <unfixed> (embed; bug #383422)
1487            - miro <unfixed> (embed; bug #555351)
1488            - calibre <unfixed> (embed; bug #555352)
1489            - freevo <unfixed> (embed; bug #555353)
1490            - pida <unfixed> (embed; bug #555354)
1491            - planet-venus <unfixed> (embed; bug #555355)
1492            - plone3 <removed> (embed; bug #555356)
1493            - exaile 0.2.14+debian-1 (embed)
1494            - screenlets 0.1.2-3 (embed)
1495            NOTE: included twice
1496    
1497    agg:
1498            - matplotlib <unfixed> (embed: bug #377271)
1499            - contextfree <unfixed> (embed)
1500            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1501            - exactimage <unfixed> (embed)
1502            - python-enable <unfixed> (embed)
1503            - mapnik 0.5.1-3 (embed)
1504            NOTE: links statically to agg, but shared library is not available (bug #377271)
1505    
1506    vtk
1507            - paraview <unfixable> (embed; bug #495426)
1508    
1509    txt2tags
1510            - rednotebook <unfixed> (embed)
1511    
1512    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1513            - gajim <unfixed> (embed)
1514            - emesene <unfixed> (embed)
1515            - convirt <unfixed> (embed)
1516            - pida <unfixed> (embed)
1517            - rednotebook <unfixed> (embed)
1518    
1519    horde3 (prototype.js is among the embeds in the following)
1520            - mnemo2 <unfixed> (embed)
1521            - nag2 <unfixed> (embed)
1522            - wordpress <unfixed> (embed)
1523            NOTE: Text_Diff (wp-includes/Text/Diff*)
1524    
1525    cimg
1526            - gmic <unfixed> (embed)
1527    
1528    mootools
1529            - kdenetwork <unfixed> (embed)
1530            - gallery <unfixed> (embed)
1531            - jspwiki <unfixed> (embed)
1532            - vdr-plugin-live <unfixed> (embed)
1533            - perl-doc-html <unfixed> (embed)
1534    
1535    openldap
1536            - openldap2.3 <removed> (old-version)
1537    
1538    grub2
1539            - grub <unfixed> (old-version)
1540    
1541    gnupginterface
1542            - duplicity <unfixed> (embed)
1543    
1544    python-dateutil
1545            - awn-extras-applets <unfixed> (embed)
1546            - matplotlib <unknown> (embed)
1547    
1548    cups
1549            - cupsys <removed> (old-version)
1550    
1551    yui
1552            - bcfg2 <not-affected> (present in source but not included in any binary files)
1553            - serendipity 1.5.3-1 (embed; bug #557746)
1554            - moodle 1.8.2.dfsg-5 (embed)
1555            - jifty 0.91117-1 (embed; bug #557748)
1556            - webgui 7.7.26-1 (embed)
1557            - loggerhead 1.17-1 (embed)
1558            - otrs2 2.4.7+dfsg1-1 (embed; bug #592146)
1559    
1560    quake3 (vanilla source not packaged in debian)
1561            - openarena <unfixable> (fork)
1562    
1563    quake2 (vanilla source not packaged in debian)
1564            - alien-arena <unfixable> (fork)
1565            - warsow <unfixable> (fork)
1566    
1567    libtheora
1568            - iceweasel <not-affected> (uses xulrunner)
1569            - xulrunner <unfixed> (embed; bug #540959)
1570            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1571            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1572            - iceape <unfixed> (embed; bug #559276)
1573            [etch] - iceape <not-affected> (introduced in iceape 2.0)
1574            [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1575    
1576    dtoa
1577            - bfilter <unfixed> (embed)
1578            - cacao <removed> (embed)
1579            - cdrdao <unfixed> (embed)
1580            - classpath <unfixed> (embed)
1581            - freej <unfixed> (embed)
1582            - iceape <unfixed> (embed)
1583            - iceweasel <unfixed> (embed)
1584            - jscoverage <unfixed> (embed)
1585            - kde4libs <unfixed> (embed)
1586            - kdelibs <unfixed> (embed)
1587            - kompozer <unfixed> (embed)
1588            - libv8 <unfixed> (embed)
1589            - mono <unfixed> (embed)
1590            - newlib <unfixed> (embed)
1591            - nspr <unfixed> (embed)
1592            - php5 <unfixed> (embed)
1593            - polyml <unfixed> (embed)
1594            - qt4-x11 <unfixed> (embed)
1595            - rhino <unfixed> (embed)
1596            NOTE: code translated to Java
1597            - ruby1.8 <unfixed> (embed)
1598            - ruby1.9 <unfixed> (embed)
1599            - ruby1.9.1 <unfixed> (embed)
1600            - sdd <unfixed> (embed)
1601            - sfind <unfixed> (embed)
1602            - star <unfixed> (embed)
1603            - tinymux <unfixed> (embed)
1604            - virtualbox-ose <unfixed> (embed)
1605            - webkit <unfixed> (embed)
1606            - xulrunner <unfixed> (embed)
1607    
1608    ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1609            - firegpg <unfixed> (embed)
1610            - enigmail <unfixed> (embed)
1611    
1612    ptmalloc (not packaged in Debian)
1613            - crystalspace <unfixed> (embed)
1614            - qt4-x11 <unfixed> (embed)
1615    
1616    svgalib
1617            - usplash <unfixed> (embed)
1618    
1619    bogl
1620            - usplash <unfixed> (embed)
1621    
1622    taglist
1623            - usplash <unfixed> (embed)
1624    
1625    portaudio
1626            - audacity <unfixed> (embed; bug #323711)
1627    
1628    nyquist
1629            - audacity <unfixed> (embed)
1630            NOTE: embeds a forked nyquist with support for a shared library
1631    
1632  imagemagick:  vamp-plugin-sdk
1633  graphicsmagick          - audacity <unfixed> (embed)
1634    
1635  halibut:  wordpress
1636  nsis          - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1637            - wordpress-mu <removed> (fork)
1638    
1639  libghttp:  php5
1640  hotway          - php4 <removed> (old-version)
1641    
1642  etl-dev (will be renamed to libetl-dev soon):  classpath
1643  synfig          - libgnucrypto-java <removed> (embed; bug #559788)
1644    
1645  libphp-adodb:  libtool
1646  moodle          - apr <unfixed> (static; bug #489625)
1647  cacti (dependency exists, but internal version is used -- only in sarge, fixed in etch)          NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1648            - arts <unfixed> (embed)
1649            - bochs 2.4.2-1 (embed; bug #560884)
1650            - camserv <unfixed> (embed)
1651            - collectd 4.8.2-1 (embed)
1652            - courier-authlib 0.58-4 (embed)
1653            NOTE: The etch version of courier-authlib was the earliest version checked, might be fixed earlier
1654            - cvsnt 2.5.04.3236-1.2 (embed)
1655            - dico <not-affected> (Uses the system copy of ltdl)
1656            - freeradius 0.1+20010527-1 (embed)
1657            NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1658            - ggobi 2.1.9~20091212-1 (embed)
1659            - glame 2.0.1-4 (embed)
1660            NOTE: The etch version of glame was the earliest version checked, might be fixed earlier
1661            - gnash 0.8.7-2 (embed)
1662            - gnu-smalltalk <unfixed> (embed; bug #566777)
1663            - google-gadgets 0.10.5-0.3 (embed)
1664            NOTE: 0.10.5-0.3 was the earliest version checked, was fixed earlier
1665            - graphicsmagick 1.3.5-6 (embed)
1666            - graphviz 2.8-3 (embed)
1667            NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1668            - guile-1.6 1.6.8-7 (embed)
1669            - hamlib 1.2.11-1 (embed)
1670            - hercules 3.06-1.2 (embed)
1671            - jags 1.0.4-3 (embed; bug #560864)
1672            - kdelibs <unfixed> (embed)
1673            - libannodex <removed> (embed)
1674            - libextractor 0.5.23+dfsg-4 (embed)
1675            - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1676            - libtunepimp 0.5.3-7.3 (embed)
1677            - mp4h 1.3.1-4.1 (embed)
1678            - naim <removed> (embed)
1679            - parser-mysql <unfixed> (embed)
1680            - pinball 0.3.1-11 (embed)
1681            - redland <unfixed> (embed)
1682            - siproxd <unfixed> (embed)
1683            - ski <unfixed> (embed)
1684            - synfig 0.62.00-1 (embed)
1685            - unixodbc 2.2.4-5 (embed)
1686            - xmlsec1 <not-affected> (Doesn't enable dynamic loading of crypto modules)
1687            - clamav 0.95+dfsg-1 (embed)
1688            - imagemagick 6:6.2.3.1-1 (embed)
1689            - hypre 2.4.0b-5 (embed)
1690            - lam <unfixed> (embed)
1691            - openmpi <unfixable> (embed; bug #559386)
1692            - parser <unfixed> (embed)
1693            - pdsh 2.18-5 (embed; bug #560892)
1694            - sbnc 1.2-8 (embed)
1695            - sdcc <unfixed> (embed)
1696            - wml <not-affected> (The embedded ltdl isn't used, instead mp4h is used, see 559841)
1697            - proftpd-dfsg <unfixed> (embed; bug #561748)
1698            - babel 1.4.0.dfsg-5 (embed)
1699            - libprelude 0.9.14-2 (embed)
1700            - heartbeat 2.1.4-7 (embed)
1701            NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1702            NOTE: might've been fixed earlier
1703            - gcc-* <unknown> (embed)
1704    
1705    ocamlgsl
1706            - orpie 1.5.1-7.1 (embed; bug #550058)
1707    
1708    xdotool
1709            - keynav <unfixed> (embed; bug #560103)
1710    
1711    bulletphysics (not packaged; http://www.bulletphysics.org/)
1712            - supertuxkart <unfixed> (embed)
1713            - blender <unfixed> (embed)
1714    
1715    ghostscript
1716            - gs-gpl <removed> (old-version)
1717    
1718    icedove
1719            - thunderbird <removed> (old-version)
1720    
1721    sizzlejs (not packaged in Debian, http://sizzlejs.com/)
1722            - jquery <unfixed> (embed)
1723    
1724    sed
1725            - ssed <unfixed> (fork)
1726    
1727    phpatomlib (http://code.google.com/p/phpatomlib)
1728            - wordpress <unfixed> (embed)
1729    
1730    Services_JSON (http://pear.php.net/package/Services_JSON)
1731            - wordpress <unfixed> (embed)
1732    
1733    phpass (http://www.openwall.com/phpass/)
1734            - gallery2 <unfixed> (embed)
1735            - wordpress <unfixed> (embed)
1736            - typo3-src <unfixed> (modified-embed)
1737            NOTE: file refers to drupal, maybe there's a copy somewhere there
1738            NOTE: a copyright owner search didn't match anything
1739            - libauthen-passphrase-perl <unfixable> (fork)
1740            NOTE: perl implementation of phpass
1741    
1742    squirrelmail
1743            - wordpress <unfixed> (embed)
1744            NOTE: class-pop3.php
1745    
1746    ezSQL (http://www.woyano.com/jv/ezsql)
1747            - wordpress <unfixable> (fork)
1748            NOTE: wp-db.php
1749    
1750    Diff.php (Clay Loveless' version/killersoft.com)
1751            - php-versioncontrol-svn <unfixed>
1752    
1753    libm (provided by libc)
1754            - spring <unfixed> (embed)
1755            NOTE: embedded by embedded copy of streflop
1756            - aide <unfixed> (static)
1757            - busybox <unfixed> (static)
1758            - mindi-busybox <unfixed> (static)
1759            - qemu <unfixed> (static)
1760            NOTE: qemu-user-static
1761            - tuxonice-userui <unfixed> (static)
1762            - zsh <unfixed> (static)
1763            NOTE: zsh-static
1764            - tripwire <unfixed>
1765    
1766    streflop
1767            - spring <unfixed> (embed)
1768    
1769    minizip
1770            - spring <unfixed> (embed)
1771    
1772    oscpack
1773            - spring <unfixed> (embed)
1774    
1775    hpiutil2
1776            - spring <unfixed> (embed)
1777    
1778    p7zip
1779            - spring <unfixed> (embed)
1780    
1781    pythonqt (doesn't seem to be python-qtN, unknown source)
1782            - fontmatrix <unfixed> (embed)
1783            - elmerfem <unfixed> (embed)
1784    
1785    iepngfix (not packaged in Debian; http://www.twinhelix.com/css/iepngfix/)
1786            - docvert <unfixed> (embed)
1787            - jifty <unfixed> (embed)
1788            - kdenetwork <unfixed> (embed)
1789            - mediatomb <unfixed> (embed)
1790            - plastex <unfixed> (embed)
1791            - plone3 <removed> (embed)
1792            - python-chaco <unfixed> (embed)
1793            - python-docutils <unfixed> (embed)
1794            - s5 <unfixed> (embed)
1795            - zope2.10 <unfixed> (embed)
1796            - zope2.11 <removed> (embed)
1797            - cython <not-affcted> (embed)
1798            NOTE: part of documentation, which is not installed into the binary package
1799    
1800    python-docutils
1801            - zope2.10 <unfixed> (embed)
1802            - zope2.11 <removed> (embed)
1803    
1804    tesseract
1805            - ocropus <unfixed> (static)
1806    
1807    antlr
1808            - kdevelop <unfixed> (embed)
1809    
1810    libxerces2
1811            - openjdk-6 <unfixed> (embed)
1812    
1813    kfreebsd-8
1814            - kfreebsd-7 <unfixed> (old-version)
1815            - kfreebsd-6 <removed> (old-version)
1816    
1817    ruby1.9.1
1818            - ruby1.9 <unfixed> (old-version)
1819            - ruby1.8 <unfixed> (old-version)
1820    
1821    maildrop
1822            - courier <unfixed> (embed) [./maildrop]
1823    
1824    glee
1825            - warzone2100 <not-affected> (embed)
1826    
1827    phing
1828            - symfony <unfixed> (embed)
1829    
1830    pake
1831            - symfony <unfixed> (embed)
1832    
1833    propel
1834            - symfony <unfixed> (embed)
1835    
1836    creole
1837            - symfony <unfixed> (embed)
1838    
1839    hfsutils
1840            - cdrkit <unfixed> (embed; bug #570187)
1841            NOTE: embeds hfsutils code in genisoimage
1842    
1843    cdrkit
1844            - grub2 <unfixed> (embed; bug #570156)
1845            NOTE: genisoimage imported into grub-mkisofs
1846    
1847    kdebase-workspace
1848            - kdebase <unfixed> (old-version)
1849    
1850    file
1851            - php5 <unfixable> (modified-embed)
1852            [lenny] - php5 <not-affected>
1853    
1854    cdb
1855            - php5 <unfixed> (embed)
1856    
1857    libmbfl (itp: #570708)
1858            - php5 <unfixed> (embed)
1859            NOTE: PHP is actually the current upstream, ITP is of that code
1860    
1861    libonig
1862            - php5 5.3.2-1 (embed)
1863    
1864    xmlrpc-epi
1865            - php5 <unfixed> (embed)
1866    
1867    swt-gtk
1868            - eclipse <unfixed> (embed; bug #538808)
1869    
1870    txt2html
1871            - wml 2.0.11ds2-1 (embed)
1872    
1873    ca-certificates
1874            - nss <not-affected> (certificates are in source, but not included in any of the binary packages)
1875    
1876    openexr
1877            - freeimage <unfixed> (embed)
1878    
1879    libmng
1880            - freeimage <unfixed> (embed)
1881    
1882    openjpeg
1883            - freeimage <unfixed> (embed)
1884    
1885    libjpeg6b
1886            - freeimage <unfixed> (embed)
1887    
1888    libjpeg (don't know what exact version)
1889            - dcmtk <unfixed>
1890            - gdcm <unfixed>
1891            - insighttoolkit <unfixed>
1892            - openarena 0.8.5-5+exp1 (bug #495966)
1893            - outguess <unfixed>
1894            - squeak-vm <unfixed> (embed)
1895            - tremulous <unfixed>
1896            - tuxonice-userui <unfixed> (static)
1897            - fpc <unfixed> (static)
1898            - lazarus <unfixed> (static)
1899            NOTE: inherited from fpc, see #472304
1900            - mseide-msegui <unfixed> (static)
1901            NOTE: inherited from fpc, see #472304
1902            - easymp3gain <unfixed> (static)
1903            NOTE: inherited from fpc, see #472304
1904            - winff <unfixed> (static)
1905            NOTE: inherited from fpc, see #472304
1906            - texlive-bin <not-affected> (included in upstream source as dependency of libgd2, but not built or included in any of the binary packages)
1907    
1908    
1909    lxr
1910            - lxr-cvs <unfixed> (embed)
1911    
1912    libfile-copy-recursive-perl
1913            - r-base <unfixed> (embed; bug #577427)
1914            - r-base-core-ra <unfixed> (embed; bug #577429)
1915    
1916    delimmatch
1917            - r-base <unfixed> (embed; bug #577433)
1918            - r-base-core-ra <unfixed> (embed; bug #577434)
1919    
1920    libsmf (ITP: #572558)
1921            - denemo <unfixed> (embed)
1922            NOTE: http://lists.debian.org/debian-mentors/2010/04/msg00269.html
1923    
1924    libselinux
1925            - dpkg 1.15.6 (static)
1926    
1927    xinha (ITP: #479708)
1928            - horde3 <unfixed>
1929            - serendipity <unfixed>
1930            - openacs <unfixed>
1931            - dotlrn <unfixed>
1932    
1933    dvipng
1934            - texlive-bin <not-affected> (code present in source but not included in the binary packages)
1935    
1936    dvipdfmx
1937            - texlive-bin <unfixed> (embed)
1938            NOTE: this is intentionally part of the package now, and the separate dvipdfmx package has been removed from sid/squeeze
1939    
1940    lcdf-typetools
1941            - texlive-bin 2009-1 (embed)
1942    
1943    tex4ht
1944            - texlive-bin 2009-1 (embed)
1945    
1946    freetype
1947            - texlive-bin 2009-1 (embed)
1948    
1949    freetype2
1950            - texlive-bin 2009-1 (embed)
1951    
1952    silgraphite
1953            - texlive-bin <unfixed> (embed)
1954    
1955    unzip
1956            - texlive-bin 2009-1 (embed)
1957    
1958    jbig2dec
1959            - ghostscript 8.71~dfsg2-1 (embed)
1960    
1961    libxml2
1962            - chromium-browser 5.0.375.29~r46008-1
1963    
1964    protobuf
1965            - chromium-browser 5.0.375.70~r48679-2
1966    
1967    libv8
1968            - chromium-browser 5.0.375.38~r46659-1
1969    
1970    nspr
1971            - chromium-browser 5.0.375.29~r46008-3
1972    
1973    yasm
1974            - chromium-browser 5.0.375.29~r46008-2
1975    
1976    libxslt
1977            - chromium-browser 5.0.375.29~r46008-1
1978    
1979    miniupnpc (not packaged in Debian; ITP bug #444392)
1980            - warzone2100 <unfixed> (embed)
1981    
1982    iniparser (not packaged in Debian; RFP bug #582657)
1983            - warzone2100 <unfixed> (modified-embed)
1984    
1985    pyglet
1986            - sympy <unfixed> (embed; bug #459716)
1987    
1988  libmms:  mpmath
1989  xine-lib          - sympy <unfixed> (embed; bug #541746)
 mimms  
1990    
1991  FCKeditor:  curl
1992  knowledgeroot          - criticalmass <unfixed> (static; bug #599061)
   
 TinyMCE:  
 wordpress  
 moodle  
 knowledgeroot  
 joomla (ITP)  
   
 scintilla:  
 scite  
 qscintilla  
 geany  
   
 libphp-adodb:  
 gallery2  
 phppgadmin  
 egroupware  
 phpwiki  
 moodle  
   
 gzip:  
 linux-kernel (lib/inflate.c)  
 klibc (based on linux-kernel gzip code)  
 busybox  
1993    
1994    lib3ds
1995            - boson <unfixed> (embed; bug #600900)

Legend:
Removed from v.4827  
changed lines
  Added in v.15492

  ViewVC Help
Powered by ViewVC 1.1.5