/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 4835 by neilm, Mon Oct 9 20:39:54 2006 UTC revision 13423 by pabs, Wed Dec 2 10:34:45 2009 UTC
# Line 1  Line 1 
1    Embedded code copies
2    ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects, without linking dynamically:  This is considered bad for fixing security flaws because the fix needs
6    to be applied in multiple source packages.
7    
8    Format:
9    <srcpkg> (<optional comment about srcpkg>)
10            - <embedding srcpkg> <status> (<sort>; bug #<number>)
11            NOTE: optional comments about the linkage of the embedding srcpkg
12    
13    status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp>, <not-affected>, <unknown> if the version number can not
15            be determined, or <unfixable> for unavoidable cases (e.g., forks
16            that add real value)
17    sort: static (linking statically against a lib)
18          embed (embedding a copy of the library into another source package)
19          fork (the package is not just embedding code but it is a fork and
20                thus might share parts of the source code)
21          old-version (the package is an older version of essentially
22                       the same code)
23    
24    The srcpkg might be some string to identify the code if there is no
25    specific source package.
26    
27    Everything up to the next line is ignored.
28    ---BEGIN
29    xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
30            NOTE: Fixed packages link to poppler library unless otherwise noted
31            - pdftohtml <unknown>
32            [sarge] - pdftohtml <unfixed>
33            [etch] - pdftohtml <unfixed>
34            NOTE: has been replaced by poppler-utils
35            - kdegraphics 4:4.2.2-1 (embed; bug #436164)
36            - texlive-base 3.0-12 (embed)
37            - texlive-bin 2007-1 (embed)
38            NOTE: links to poppler
39            - koffice <unfixed> (embed; bug #436163)
40            - libextractor 0.5.12-1 (embed)
41            NOTE: libextractor is using its own pdf decoder now
42            - ipe <unfixed> (embed)
43            NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44            - ruby-gnome2 <unknown> (embed)
45            NOTE: copy only present in source but links to poppler
46            - pdfedit <unfixed> (embed; bug #510794)
47            - swftools <unfixed> (embed; bug #551293)
48            - poppler <unfixable> (fork)
49    
50    ppmd
51            - libcomplearn-mod-ppmd <unfixed> (fork)
52            NOTE: discussion in #458152
53    
54    libevent
55            - transmission 1.71-1 (embed; bug #529372)
56    
57    lrmi
58            - read-edid 2.0.0-1 (embed; bug #495131)
59    
60    peercast
61            - gnome-peercast <removed> (embed)
62            [etch] - gnome-peercast <unfixed> (embed)
63    
64    silc-toolkit
65            - silc-client 1.1~beta6-1 (embed)
66    
67    icclib
68            - ghostscript <unfixed> (embed)
69            - argyll <unfixed> (embed)
70    
71    dietlibc
72            - ccontrol 0.9.1+20071204-1 (static)
73    
74    libmikmod
75            - sdl-mixer1.2 <unfixed> (embed)
76            TODO: report bug
77    
78    libiax
79            - iaxmodem <unfixable> (embed; bug #548885)
80    
81    spandsp
82            - iaxmodem <unfixable> (embed; bug #548885)
83    
84    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
85            - dpkg <unfixed> (embed)
86            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
87            - rsync <unfixed> (embed)
88            NOTE: somehow derived code base
89            - mono <unfixed> (embed)
90            TODO: check mozilla
91            - Linux kernels <unfixed> (embed)
92            - pvpgn 1.7.8-2 (embed)
93            - mrtg 2.12.2-1 (embed)
94            - rpm <unknown> (embed)
95            NOTE: pinged anibal since when rpm was fixed
96            - tuxcmd-modules <unfixed> (embed)
97            - zsync <unfixed>
98            - tra <unfixed>
99            - sash <unfixed>
100            - nsis <unfixed>
101            - mseide-msegui <unfixed>
102            NOTE: mseide
103            - mirrordir <unfixed>
104            - poco <unfixed>
105            - klibc <unfixed>
106            - ghostscript <unfixed>
107            - freeimage <unfixed>
108            - clamav <unfixed> (fork)
109            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
110            - tuxonice-userui <unfixed>
111            - plt-scheme <unfixed>
112            - perl <unfixed>
113            - paraview <unfixed>
114            - gcvs <unfixed>
115            - dump <unfixed>
116            - aide <unfixed> (static)
117            - dar <unfixed> (static)
118            - avfs <unfixed>
119            - fpc <unfixed>
120            - winff <unfixed>
121            NOTE: inherited from fpc, see #472304
122            - lazarus <unfixed>
123            NOTE: inherited from fpc, see #472304
124            - erlang <unfixed> (embed)
125            - gamera 3.2.3-1 (embed)
126            - python2.4 <unfixed> (embed; bug #553403)
127            - python2.5 <unfixed> (embed; bug #553403)
128    
129    dulwich
130            - hg-git 0.1.0-1 (embed; bug #541996)
131    
132    libvigraimpex
133            - hugin <unfixed> (embed; bug #542259)
134            - enblend-enfuse <unfixed> (embed; bug #542258)
135            - gamera 3.2.3-1 (embed)
136    
137    libbz2
138            - dpkg <unfixed> (static)
139    
140    libgadu
141            - centericq <unfixed> (embed)
142            - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
143            - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
144            - kdenetwork 4:3.3.2-5 (embed)
145            NOTE: from kdenetwork: kopete
146            - ekg 1:1.8~rc0-1 (embed)
147            - kadu 0.6.0.2-3 (embed; bug #504430)
148            - gadu <itp> (embed)
149    
150    xmlrpc (which package is the "origin" of this code?)
151            - drupal <unfixed> (embed)
152            - phpgroupware <unfixed> (embed)
153            - egroupware <unfixed> (embed)
154            - phpwiki <unfixed> (embed)
155            - php4 <unfixed> (embed)
156            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
157    
158    shtool (affects build-time only)
159            - mysql-ocaml <unfixed> (embed)
160            - php4 <unfixed> (embed)
161    
162    iceape
163            - iceweasel <unfixed> (fork)
164            - icedove <unfixed> (fork)
165            - xulrunner <unfixed> (fork)
166            - kompozer <unfixed> (embed; bug #532168)
167            - galeon <unfixed> (fork)
168            - epiphany-browser <unfixed> (fork)
169            - conkeror <unfixed> (fork)
170            - kazehakase <unfixed> (fork)
171    
172    xli
173            - xloadimage <unfixed> (embed)
174    
175    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
176            - openmotif <unfixed> (embed)
177            - libxpm <unfixed> (embed)
178    
179    kerberized apps with BSD origin
180            - krb4 <removed> (embed)
181            - krb5 <unfixed> (embed)
182            - heimdal <unfixed> (embed)
183    
184    grip (which pkg is the origin?)
185            - libcdaudio <unfixed>
186            - grip <unfixed>
187            - gnome-vfs <unfixed>
188            TODO: check vfs2 as well
189    
190    fudforum
191            [etch] - phpgroupware <unfixed> (embed)
192            NOTE: phpgroupware-fudforum
193            [sarge] - egroupware-fudforum <removed> (embed)
194    
195    libbsd
196            - rdate 1:1.2-3 (embed)
197            - atheme-services <unfixed>
198            - libbsd-arc4random-perl <unfixed>
199            - isakmpd <unfixed>
200    
201    cvs
202            - gcvs <unfixed> (embed)
203            NOTE: see cvsunix/src in tarball
204    
205    pcre3
206            - php4 <unknown> (embed)
207            - analog 2:5.23-0woody1 (embed)
208            - goffice <unfixed> (embed)
209            NOTE: libgoffice-*
210            - vfu 4.06-4.1 (embed; bug #450754)
211            - tf5 5.0beta7-1 (embed)
212            - monotone 0.43-1 (embed)
213            NOTE: this only affects versions >= 0.37
214            - glib2.0 2.15.2-1 (embed)
215            - apache2 2.0.53-4 (embed)
216            - exim4 4.10-0.srh20.12 (embed)
217            - yacas <unfixed> (embed)
218            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
219            - gtamsanalyzer.app 0.42-5 (embed)
220            - tin 980117-1 (embed)
221            - kazehakase 0.5.2-1
222            - webkit 1.0.1-1 (embed)
223            - qt4-x11 <unfixed> (embed)
224            NOTE: embedded via webkit copy
225            - erlang <unfixed> (embed)
226    
227    tiff
228            - wxwindows2.4 2.2.1 (embed)
229            - gamera 3.2.3-1 (embed)
230    
231    uudeview
232            - libconvert-uulib-perl <unfixed> (embed)
233            - pan <unfixed> (embed)
234    
235    sqlite (not affected by security vulnerabilities so far)
236            - amarok <unfixed> (embed)
237            - monotone 0.43-1 (embed)
238            - iceweasel <unfixed> (embed)
239    
240    util-linux/mount
241            - loop-aes-utils <unfixed> (embed)
242            NOTE: contains code from util-linux' mount in the mount-aes-udeb
243    
244    sylpheed
245            - sylpheed-claws <unfixed> (fork)
246    
247    phpsysinfo
248            - egroupware <unfixed> (embed)
249            - phpgroupware <unfixed> (embed)
250    
251    phpldapadmin
252            [sarge] - egroupware <unfixed> (embed)
253            NOTE: removed from egroupware after sarge
254    
255    chmlib
256            - kchmviewer <unknown> (embed)
257    
258    ffmpeg (libavcodec/libavformat)
259            - mplayer 1.0~rc2-14 (embed; bug #395252)
260            - kino 1.0.0-1
261            - vlc <not-affected> (Links dynamically since initial release)
262            - smilutils 0.3.0-10
263            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
264            - motion 3.1.19-1
265            - gstreamer0.10-ffmpeg 0.10.3-2
266            - xmovie <removed> (static)
267            TODO: gimp-gap (potentially using ffmpeg code as well)
268            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
269    
270    faad2
271            - mplayer 1.0~rc2-20 (embed)
272            - avifile <unfixed> (embed; bug #538750)
273            - ffmpeg-debian <removed> (old-version)
274    
275    libmad (MPEG decoding lib)
276            - xine-lib <unfixed> (embed)
277            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
278            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
279    
 xpdf code: (some use xpdf 2, some xpdf 3)  
 gpdf (will be replaced by evince in Gnome 2.12)  
 pdftohtml (current poppler source package has a ported version, pinged maintainer)  
 kdegraphics/kpdf (upstream is working on using poppler, probably not in time for Etch)  
 tetex-bin (links to poppler since 3.0-12)  
 cupsys (only older releases, recent ones use xpdf-utils, it's still present in the src, though)  
 poppler  
 koffice (upstream is working on using poppler, probably not in time for Etch)  
 libextractor (uses internal pdf decoder since 0.5.12-1)  
 pdfkit.framework (links to poppler since 0.8-4)  
   
 zlib code: (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  
 dpkg  
 rsync (somehow derived code base)  
 mozilla(?)  
 Linux kernels  
 pvpgn (links dynamically since 1.7.8-2)  
 mrtg (links dynamically since 2.12.2-1)  
   
 libgadu/ekg:  
 centericq  
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not yet packaged in Debian)  
   
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki (not packaged in Debian)  
   
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 nvu  
   
   
 xli:  
 xloadimage  
   
   
 lesstif: (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm)  
   
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum  
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 all pythons  
 php4 (src included, but Debian package links dynamically)  
 analog (src included, but Debian package links dynamically)  
 libgoffice-1  
 tf5 (since 5.0beta7 the Debian package links dynamically)  
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
   
   
 uudeview:  
 libconvert-uulib-perl  
   
 sqlite: (not affected by security vulnerabilities so far)  
 amarok  
   
 util-linux/mount:  
 loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb  
   
 webmin:  
 usermin  
   
 sylpheed:  
 sylpheed-claws  
   
 phpsysinfo:  
 egroupware  
 phpgroupware  
   
 phpldapadmin:  
 egroupware  
   
 chmlib:  
 kchmviewer (not packaged in Debian)  
   
 libavcodec/libavformat:  
 ffmpeg  
 xine-lib  
 xvidcap (currently in NEW)  
 kino (links statically, does not include code)  
 vlc (links statically, does not include code)  
 smilutils (links statically, does not include code)  
 motion (links statically, does not include code)  
 gst-ffmpeg  
 xmovie (currently in NEW)  
 gst-ffmpeg  
   
 mad MPEG decoding lib:  
 mad  
 xine-lib  
   
 libdts:  
280  libdts  libdts
281  xine-lib          - xine-lib <unfixed> (embed)
282    
 flac:  
283  flac  flac
284  xine-lib          - xine-lib <unfixed> (embed)
   
 liba52:  
 a52dec  
 xine-lib  
   
 libmpeg2:  
 mpeg2dec  
 xine-lib  
   
 curl:  
 wget (code for NTLM authentication)  
285    
286  TODO evaluate:  liba52
287  gimp-gap (potentially using ffmpeg code as well)          - a52dec <unfixed> (embed)
288            - xine-lib <unfixed> (embed)
289    
290    libmpeg2
291            - mpeg2dec <unfixed> (embed)
292            - xine-lib <unfixed> (embed)
293    
294    libntlm
295            - wget <unfixed> (fork; bug #550436)
296            - curl <unfixed> (fork; bug #550437)
297            - cntlm <unfixed> (fork; bug #550438)
298    
299    uw-imap
300            - pine <unfixed> (embed)
301            - alpine <unfixed> (embed)
302    
303    imagemagick
304            - graphicsmagick <unfixed> (fork)
305    
306    python-urlgrabber
307            - mercurial <unfixed> (embed; bug #531062)
308            - w3af <unfixed> (embed; bug #555372)
309            [experimental] - harvestman <unfixed> (embed; bug #555373)
310    
311    beautifulsoup
312            - python-mechanize <unfixed> (embed; bug #555349)
313            - zope2.11 <unfixed> (embed; bug #555350)
314            - twill <unknown> (embed)
315    
316    halibut
317            - nsis <unfixed> (fork)
318    
319    libghttp
320            - hotway <unfixed> (embed)
321    
322    libsndfile
323            - ardour 1:2.7.1-1 (embed)
324    
325    glibmm2.4
326            - ardour 1:2.7.1-1 (embed)
327    
328    libgnomecanvasmm2.6
329            - ardour 1:2.7.1-1 (embed)
330    
331    libsigc++-2.0
332            - ardour 1:2.7.1-1 (embed)
333    
334    soundtouch
335            - ardour 1:2.7.1-1 (embed)
336    
337    libmms
338            - xine-lib <unfixed> (embed)
339            - mimms <unfixed> (embed)
340    
341    fckeditor
342            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
343            - moin 1.8.2-2 (embed; bug #452599)
344            - karrigell <removed> (embed; bug #452598)
345            - gforge 4.6.99+svn6225-1 (embed)
346            - request-tracker3.8 <unfixed> (embed)
347    
348    ipatlas (not packaged in Debian)
349            - moodle <unfixed> (embed; bug #507185)
350    
351    libphp-phpmailer
352            - moodle <unfixed> (embed; bug #507185)
353            - mahara <unfixed> (embed)
354            - symfony <unfixed> (embed)
355            [etch] - phpgroupware <unfixed> (embed)
356            NOTE: phpgroupware-felamimail is only in etch
357            - egroupware <unfixed> (embed; bug #504283)
358            - glpi <unfixed>
359    
360    htmlArea (not packaged in Debian)
361            - moodle <unfixed> (embed)
362    
363    giflib
364            - wine <unfixed> (embed; bug #466181)
365    
366    bennu (not packaged in Debian, http://bennu.sourceforge.net)
367            - moodle <unfixed> (embed)
368    
369    smarty
370            - moodle 1.8.2-2 (embed; bug #471158)
371            - gallery2 2.2.5-2 (embed; bug #471160)
372            - mahara 0.9.2-2 (embed; bug #471201)
373            - gosa 2.4beta1-1 (embed; bug #471200)
374    
375    TinyMCE
376            - wordpress 2.5.1-3 (embed; bug #478257)
377            - moodle <unfixed> (embed; bug #507185)
378            - knowledgeroot <unfixed> (embed)
379            - joomla <itp> (bug #326398)
380    
381    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
382            - scite <unfixed> (embed)
383            - qscintilla <unfixed> (embed)
384            - qscintilla2 <unfixed> (embed)
385            - geany <unfixed> (fork)
386            - anjuta <unfixed> (embed)
387    
388    libphp-adodb
389            - moodle <unfixed> (embed; bug #507185)
390            NOTE: also AdoDB-XML Schema
391            - gallery2 <unfixed> (embed)
392            - phppgadmin <unfixed> (embed)
393            - egroupware <unfixed> (embed)
394            - phpwiki <unfixed> (embed)
395            - torrentflux 2.0beta1-2 (embed)
396            - ipplan <unfixed> (embed)
397            - typo3-src <unfixed> (embed)
398            - cacti <unknown> (embed)
399            [sarge] - cacti <unfixed> (embed)
400            NOTE: dependency exists, but internal version is used
401            - gforge 4.7~rc2-6 (embed)
402            - mahara <unfixed> (embed)
403    
404    gzip
405            - linux-kernel <unfixed> (embed)
406            NOTE: lib/inflate.c
407            - klibc <unfixed> (embed)
408            NOTE: based on linux-kernel gzip code
409            - busybox <unfixed> (embed)
410    
411    neon
412            - cadaver 0.22.3+debian-1 (embed; bug #188381)
413            - gnome-vfs2 <unfixed> (embed; bug #395874)
414            [etch] - litmus <unfixed> (embed; #395875)
415            - litmus <removed> (embed; #395875)
416            [sarge] - screem <unfixed> (embed)
417            - sitecopy 1:0.16.3-5 (embed; bug #395876)
418            [etch] - tla <unfixed> (embed; bug #395877)
419            [sarge] - tla <unfixed> (embed; bug #395877)
420    
421    libmodplug
422            - gst-plugins-bad0.10 <unfixed> (embed)
423    
424    libvncserver
425            - vino <unfixed> (embed)
426    
427    putty
428            - filezilla <unfixed> (embed)
429    
430    tinyxml (not packaged in Debian)
431            - filezilla <unfixed>
432    
433    gv
434            - evince <unfixed> (embed)
435            NOTE: ps/ tree from gv 3.5.8
436            NOTE: evince-gtk is affected (a component of evince source package)
437    
438    libXbae
439            - paw <removed> (embed)
440            [etch] - paw <unfixed> (embed)
441    
442    libgtkhtml
443            - claws-mail-extra-plugins <unfixed> (fork)
444    
445    libXaw
446            - paw <removed> (embed)
447            [etch] - paw <unfixed> (embed)
448            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
449    
450    libgd2
451            - graphviz <unfixed> (embed)
452            NOTE: lib/gd seems to be 2.0.33
453            - wml <unfixed> (embed)
454            - libwmf <unfixed> (embed)
455            NOTE: derived from gd 1.6.3
456    
457    rar
458            - unrar-nonfree <unfixed> (embed)
459    
460    unrar-free (maybe this code is derived from the original rar, too?)
461            - clamav <unfixed> (embed)
462            NOTE: seems to be disabled in default config
463    
464    mplayer (DirectMedia Object loader)
465            - xine-lib <unfixed> (embed)
466            NOTE: src/libw32dll/
467            - vlc <unfixed> (embed)
468            NOTE: modules/codec/dmo/
469            - mplayer 1.0~rc2-20 (embed)
470    
471    libwpd (WordPerfect converter)
472            - openoffice.org <unfixed> (embed)
473    
474    fsplib (http://sourceforge.net/projects/fsp/)
475            - gftp <unfixed> (embed)
476            NOTE: lib/fsplib version 0.3
477    
478    sprng
479            - tree-puzzle <unfixed> (embed)
480    
481    librpcsecgss
482            - krb5 <unfixed> (embed)
483    
484    jasper
485            - ghostscript <unfixed> (embed)
486            - gs-gpl <unfixed> (embed)
487    
488    libiris
489            - psi <unfixed> (embed)
490            - kdenetwork <unfixed> (embed)
491            NOTE: kopete embeds libiris but links dynamically to libidn
492            - kdegames <unfixed> (embed)
493            NOTE: ksirk/kde4
494    
495    libidn
496            - monotone 0.43-1 (embed)
497            - psi <unfixed> (embed)
498            NOTE: psi embeds libiris which embeds libidn
499            - kdegames <unfixed> (embed)
500            NOTE: kdegames/kde4 embeds libiris which embeds libidn
501    
502    liblua
503            - monotone 0.43-1 (embed)
504            - nmap 5.00-1 (embed; bug #527997)
505            [lenny] - nmap <unfixed> (embed; bug #527997)
506            - ocropus <unfixed> (embed)
507    
508    libbotan
509            - monotone 0.43-1 (embed)
510    
511    NetXX
512            - monotone 0.43-1 (embed)
513    
514    libgc
515            - mono <unfixed> (embed)
516    
517    lzma
518            - p7zip <unfixed> (embed)
519            - xz-utils <unfixed> (fork)
520    
521    lzo
522            - grub2 <unfixed> (embed)
523    
524    yassl
525            - mysql-dfsg-5.0 <unfixed> (embed)
526    
527    pax code
528            - tar <unfixed> (embed)
529            - cpio <unfixed> (embed)
530    
531    t1lib
532            - tetex-bin 2.0.2-1 (embed)
533            - texlive-bin <unknown> (embed)
534    
535    guichan
536            - boswars <unfixed> (embed)
537            NOTE: maintainer notified us, working on it
538    
539    tolua
540            - boswars <unfixed> (embed)
541            NOTE: maintainer notified us, working on it
542            - ocropus <unfixed> (embed)
543            - freeciv <unfixed> (embed)
544    
545  uw-imap:  asio-dev
546  pine          - luxrender <removed> (embed)
547    
 imagemagick:  
 graphicsmagick  
   
 halibut:  
 nsis  
   
 libghttp:  
 hotway  
   
 etl-dev (will be renamed to libetl-dev soon):  
 synfig  
   
 libmms:  
548  xine-lib  xine-lib
549  mimms          - vlc <unfixed> (embed)
550            NOTE: only parts included in modules/access/rtsp
 FCKeditor:  
 knowledgeroot  
   
 TinyMCE:  
 wordpress  
 moodle  
 knowledgeroot  
 joomla (ITP)  
   
 scintilla:  
 scite  
 qscintilla  
 geany  
   
 libphp-adodb:  
 gallery2  
 phppgadmin  
 egroupware  
 phpwiki  
 moodle  
 cacti (dependency exists, but internal version is used -- only in sarge, fixed in etch)  
   
 gzip:  
 linux-kernel (lib/inflate.c)  
 klibc (based on linux-kernel gzip code)  
 busybox  
551    
552    netpbm
553            - tcl8.3 <unfixed> (embed)
554            - tcl8.4 <unfixed> (embed)
555            - tcl8.5 <unfixed> (embed)
556            NOTE: generic/tkImgGIF.c
557    
558    tk8.5
559            - tk8.0 <removed> (old-version)
560            - tk8.3 <unfixed> (old-version)
561            - tk8.4 <unfixed> (old-version)
562            - perl-tk <unfixable> (fork)
563    
564    samba
565            - mc 2:4.6.2~git20080311-1 (embed)
566            NOTE: maintainer is aware of this, currently searching a solution
567    
568    plib1.8.4c2
569            - boson <unfixed> (fork)
570            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
571    
572    fribidi
573            - quesoglc <unfixed> (embed)
574            NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
575    
576    glew
577            - quesoglc <unfixed> (embed; bug #489341)
578            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
579            - trigger <unfixed> (embed)
580            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
581            - trigger-rally <unfixed> (embed)
582            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
583    
584    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
585            - transcend <unfixed> (embed)
586            - cultivation <unfixed> (embed)
587            - passage <unfixed> (embed)
588            - gravitation <unfixed> (embed)
589    
590    tar
591            - libarchive <unfixed> (embed)
592            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
593    
594    cpio
595            - libarchive <unfixed> (embed)
596            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
597    
598    webkit
599            - qt4-x11 <unfixed> (embed)
600    
601    ftgl
602            - blender 2.46+dfsg-1 (embed)
603    
604    wv
605            - abiword <unfixed>
606    
607    qemu
608            - kvm <unfixed> (embed; bug #543159)
609            - xen-3 <unfixed> (embed)
610            - xen-unstable <unfixed> (embed)
611    
612    vgabios
613            - kvm <unfixed> (embed; bug #489442)
614    
615    bochs
616            - kvm <unfixed> (embed; bug #489442)
617    
618    speex
619            - vorbis-tools <unfixed> (embed)
620            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
621            - gst-plugins-good0.10 <unfixed> (embed)
622            - xine-lib <unfixed> (embed)
623            - libfishsound <unfixed> (embed)
624            - libannodex <unfixed> (embed)
625            - vlc <unfixed> (embed)
626            - xmms-speex <unfixed> (embed)
627            - libsdl-sound1.2 <unfixed> (embed)
628            - sweep <unfixed> (embed)
629    
630    libreadline
631            - magic <itp> (old-version)
632    
633    opcode
634            - ode <unfixed> (embed)
635            NOTE: opcode is not a package in debian, it is just embedded
636            NOTE: http://www.codercorner.com/Opcode.htm
637    
638    gimpact
639            - ode <unfixed> (embed)
640            NOTE: gimpact is not a package in debian, it is just embedded
641            NOTE: http://gimpact.sf.net
642    
643    mochikit
644            - mahara <unfixed> (embed)
645            NOTE: they require extra patches, still unmerged upstream
646            - ntop <unfixed> (embed)
647            - coherence 0.6.2-1 (embed)
648            - paste <unfixed> (embed)
649            - turbogears <unfixed> (embed)
650            - plone3 <unfixed> (embed)
651            - xulrunner <unfixed> (embed)
652            - libjifty-plugin-chart-perl <unfixed> (embed)
653            - sabnzbdplus <unfixed> (embed)
654            - tgmochikit <unfixed> (embed)
655    
656    prototypejs
657            - netbeans-ide 6.0.1+dfsg-2 (embed)
658            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
659            - webcit <unfixed> (embed; bug #555219)
660            - asterisk 1:1.6.2.0~rc3-1 (embed)
661            - libjson-ruby 1.1.4-1 (embed; bug #555224)
662            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
663            - horde3 <unfixed> (embed)
664            - knowledgeroot <unfixed> (embed; bug #555230)
665            - mediatomb <unfixed> (embed; bug #555233)
666            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
667            - ebug-http <unfixed> (embed; bug #555236)
668            - phpgedview <removed> (embed)
669            - poker-network <unfixed> (embed; bug #555238)
670            - rails 2.1.0-6 (embed)
671            - wordpress 2.5.0-2 (embed; bug #555243)
672            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
673            TODO: search through all of the other zope packages
674            - ampache 3.4.1-2 (embed)
675            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
676            - hobix 0.5~svn20070319-4 (embed; bug #555247)
677            - zabbix 1.6.6-4 (embed; bug #555250)
678            - chora2 <unfixed> (embed; bug #555253)
679            - gollem <unfixed> (embed; bug # 555254)
680            - jscropperui 1.2.1-1 (embed; bug #555257)
681            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
682            - ingo1 <unfixed> (embed; bug #555261)
683            - kronolith2 <unfixed> (embed; bug #555262)
684            - activeldap <unfixed> (embed)
685            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
686            - mantis <unfixed> (embed; bug #555265)
687            - otrs2 2.3.4-6 (embed; bug #555267)
688            - webcalendar <unfixed> (embed; bug #555269)
689            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
690            - jifty 0.90519-1 (embed; bug #555271)
691            - jquery <unfixed> (embed; bug #555272)
692            - passenger 2.2.5debian1-1 (embed; bug #555273)
693            - plone3 <unfixed> (embed; bug #555275)
694            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
695            - libhtml-prototype-perl <unfixed> (embed; bug #538920)
696            - xulrunner <unfixed> (embed)
697            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
698    
699    gdb
700            - insight <unfixed> (embed)
701    
702    e2fsprogs
703            - ldiskfsprogs <unfixable> (fork)
704    
705    quazip (not packaged in Debian)
706            - qcake <unfixed> (embed)
707            NOTE: starting with upstream version 0.6.4
708    
709    exo
710            - pcmanfm <unfixed> (embed; bug #499677)
711            NOTE: slightly modified source code
712    
713    java
714            - openjdk-6 <unfixed>
715            - sun-java5 <unfixed>
716            - sun-java6 <unfixed>
717    
718    libphp-snoopy
719            - ampache 3.4.1-2 (embed; bug #504169)
720            - gforge 4.6.99+svn6094-2 (embed)
721            - mahara 1.0.5-2 (embed; bug #504170)
722            - pixelpost 1.7.1-5 (embed; bug #504171)
723            - mediamate 0.9.3.6-5 (embed; bug #504172)
724            - opendb <removed> (embed; bug #504173)
725            [etch] - opendb <unfixed> (embed; bug #504173)
726            - wordpress 2.5.1-9 (embed; bug #443948)
727            - moodle <unfixed> (embed; bug #507185)
728            [etch] - phpgroupware <unfixed> (embed)
729            NOTE: phpgroupware-felamimail
730            - magpierss 0.72-3 (embed; bug #431089)
731    
732    jquery
733            - zekr <unfixed> (embed)
734            - wordpress <unknown> (embed)
735            - yocto-reader <unfixed> (embed)
736            - textpattern <unfixed> (embed)
737            - genshi 0.5.1-1 (embed)
738            NOTE: compressed file under examples/ dir
739            - prewikka <unfixed> (embed)
740            - libramaze-ruby <unfixed> (embed)
741            - drupal5 <unfixed> (embed)
742            - b2evolution <unfixed> (embed)
743            - wesnoth <unfixed> (embed)
744    
745    tablesorter (jquery plugin, not packaged yet)
746            - wesnoth <unfixed> (embed)
747    
748    kses
749            - wordpress <unfixed> (embed; bug #504242)
750            NOTE: their copy has all methods renamed to wp_<foo>
751            NOTE: kses isn't in Debian, RFP: #504240
752            - moodle <unfixed> (embed; bug #507185)
753            - egroupware <unfixed> (embed)
754    
755    magpierss
756            - wordpress <unfixed> (embed; bug #504242)
757            - moodle <unfixed>
758    
759    php-gettext
760            - wordpress 2.8.4-1 (embed; bug #504242)
761    
762    libphp-ixr (name may change, it is the Incutio XML-RPC)
763            - wordpress <unfixed> (embed; bug #504242)
764            NOTE: libphp-ixr isn't in Debian, RFP: #504236
765            - dokuwiki <unfixed> (embed)
766            - textpattern <unfixed> (embed)
767    
768    libphp-cas
769            - glpi <unfixed> (embed)
770            - moodle <unfixed> (embed; bug #505984)
771    
772    scriptaculous (prototype.js is among the embeds in the following)
773            - glpi <unfixed> (embed)
774            - libaws <unfixed> (embed; bug #555222)
775            - op-panel <unfixed> (embed)
776            - symfony <unfixed> (embed)
777            NOTE: maintainer says there are extra incompatible changes required
778            - pixelpost 1.7.1-6 (embed)
779            - webhelpers <unfixed> (embed)
780            - qwik <unfixed> (embed; bug #555241)
781            - smokeping <unfixed> (embed)
782            - turba2 <unfixed> (embed)
783            - typo3-src 4.2.3-1 (embed)
784            - request-tracker3.6 <unfixed> (embed)
785            - request-tracker3.8 <unfixed> (embed)
786            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
787            - wordpress 2.5.0-2 (embed)
788    
789    libmarkdown-php
790            - moodle <unfixed> (embed; bug #507185)
791            - pixelpost 1.7.1-6 (embed)
792    
793    php-openid
794            - wordpress-openid <itp> (embed)
795    
796    geshi
797            - dokuwiki 0.0.20080505-3.1 (embed)
798            - pgfouine 1.0-1.1 (embed)
799            - websvn 2.1.0-1 (embed)
800    
801    webcalendar
802            - gforge 4.7~rc2-6 (embed; bug #504758)
803    
804    libical
805            - kdepim <unfixed> (fork)
806            - kdepimlibs <unfixed> (fork)
807            NOTE: fixed in KDE4 post 4.1.x series
808            - claws-mail-extra-plugins <unfixed> (fork)
809    
810    libltdl3
811            - kdelibs <unfixed> (embed)
812            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
813            - synfig <unfixed> (embed)
814    
815    harfbuzz
816            - qt4-x11 <unfixed> (embed)
817    
818    libzip
819            - php5 <unfixed> (fork)
820            - odt2txt <unfixed> (embed; bug #523808)
821    
822    json.php (not packaged; should be replaced with php's built-in functions)
823            - moodle <unfixed>
824            - yui <unfixed>
825            - gallery2 <unfixed>
826            - dokuwiki <unfixed>
827            - typo3-src <unfixed>
828    
829    php-fpdf
830            - tcpdf <itp> (fork)
831            - moodle <unfixed>
832            - phpwiki <unfixed>
833            - egroupware <unfixed>
834            - ldap-account-manager <unfixed> (fork)
835    
836    tcpdf (itp: #495985)
837            - moodle <unfixed>
838            - phpmyadmin <unfixed>
839    
840    typo3
841            - moodle <unfixed>
842    
843    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
844            - moodle <unfixed>
845            - gosa <unfixed>
846    
847    php-ole (itp: #487558)
848            - moodle <unfixed>
849    
850    pieforms (http://www.catalyst.net.nz)
851            - mahara <unfixed>
852    
853    savant2 (http://phpsavant.com)
854            - egroupware <unfixed>
855    
856    rssparser (http://nwow.org)
857            - egroupware <unfixed>
858            - phpgroupware <unfixed>
859    
860    lcms
861            - openjdk-6 <unfixed> (fork)
862    
863    libphp-phplayersmenu
864            - diogenes <unfixed>
865            - phpldapadmin <unfixed>
866    
867    libphp-pclzip
868            - docvert <unfixed>
869            - moodle <unfixed>
870            - egroupware <unfixed>
871    
872    libphp-simplepie
873            - dokuwiki <unfixed>
874    
875    libphp-jpgraph
876            - egroupware <unfixed>
877    
878    php-simpletest
879            - moodle <unfixed>
880    
881    libpng
882            - iceweasel <not-affected> (uses xulrunner)
883            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
884            - iceape 1.0.13~pre080614i-0etch1 (embed)
885            - xulrunner 1.9.0.13-1 (embed)
886            [lenny] - xulrunner 1.9.0.11-0lenny1
887            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
888            - gamera 3.2.3-1 (embed)
889    
890    irssi
891            - silc-client <unfixed> (embed)
892            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
893    
894    extc
895            - mtasc <unfixed> (embed)
896            - haxe <unfixed> (embed)
897    
898    swflib
899            - mtasc <unfixed> (embed)
900            - haxe <unfixed> (embed)
901    
902    libitext-java
903            - bouncycastle 2.1.4-1 (embed)
904    
905    python-ply
906            - pyke <unfixed> (embed; bug #555363)
907            - pywbem <unfixed> (embed; bug #555364)
908            - sepolgen <unfixed> (embed; bug #555365)
909            - zope-textindexng3 <unknown> (embed)
910            - iceweasel <unknown> (embed)
911            - xulrunner <unknown> (embed)
912            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
913    
914    libdumbnet (libdnet upstream)
915            - nmap <unfixed> (fork)
916    
917    gcc-4.4
918            - gcc-mingw32 <unfixed> (embed)
919    
920    camlimages
921            - advi <unfixed> (static; bug #550441)
922    
923    memcached
924            - memcachedb <unfixed> (embed)
925    
926    yajl
927            - argyll <unfixed> (embed; bug #544223)
928            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
929    
930    nusoap
931            - gforge 4.8.2-1 (embed)
932    
933    libept
934            - adept <unfixed> (embed; bug #540649)
935    
936    libvorbis
937            - iceweasel <not-affected> (uses xulrunner)
938            - xulrunner <unfixed> (embed; bug #540959)
939            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
940            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
941    
942    cairo
943            - iceweasel <not-affected> (uses xulrunner)
944            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
945    
946    liboggz
947            - iceweasel <not-affected> (uses xulrunner)
948            - xulrunner <unfixed> (embed; bug #540949)
949            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
950            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
951    
952    
953    liboggplay
954            - iceweasel <not-affected> (uses xulrunner)
955            - xulrunner <unfixed> (embed; bug #540949)
956            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
957            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
958    
959    php-net-dnsbl
960            - serendipity <unfixed> (embed)
961    
962    php-onyx-rss
963            - serendipity <unfixed> (embed)
964    
965    php-text-wiki
966            - serendipity <unfixed> (embed)
967    
968    php-xml-rpc
969            - serendipity <unfixed> (embed)
970    
971    polarssl (does not have a shared library)
972            - pdkim <itp> (embed; bug #543150)
973            - xyssl <unfixed> (old-version)
974    
975    pidgin
976            - gaim <removed> (old-version)
977    
978    icu
979            - webkit 1.0.1-1 (embed; bug #547214)
980            - texlive-bin <unfixed> (fork)
981            NOTE: texlive upstream working with icu upstream to merge their changes
982    
983    cyrus-imapd-2.2
984            - kolab-cyrus-imapd <unfixed> (fork)
985            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
986    
987    python-cxx-dev
988            - freecad <unfixed> (embed; bug #547936)
989    
990    libzipios++-dev
991            - freecad <unfixed> (embed; bug #547941)
992    
993    linux-2.6
994            - kvm <unfixed> (embed; bug #549973) [./kernel/*]
995            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
996            - kernel-source-2.6.8 <removed> (old-version)
997            - kernel-source-2.4.27 <removed> (old-version)
998            - kernel-source-2.4.24 <removed> (old-version)
999            - kernel-source-2.2.25 <removed> (old-version)
1000            - kernel-source-2.2.20 <removed> (old-version)
1001    
1002    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1003            - kvm <unfixed> (embed) [./libfdt/*]
1004    
1005    qweb (not packaged)
1006            - ajaxterm <unfixed>
1007    
1008    opensaml2
1009            - opensaml <removed> (old-version)
1010    
1011    shibboleth-sp2
1012            - shibboleth-sp <removed> (old-version)
1013    
1014    tuxonice-userui
1015            - suspend2-userui <removed> (old-version)
1016    
1017    expat
1018            - w3c-libwww <removed> (embed; bug #551941)
1019            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1020            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1021            - python2.5 <unfixed> (embed; bug #553403) [./Modules/expat/*]
1022            - python2.4 <unfixed> (embed; bug #553403)
1023            - wxwindows2.4 <removed> (embed)
1024            - wxwidgets2.6 <unfixed> (embed)
1025            - wxwidgets2.8 <unfixed> (embed)
1026            - celementtree <unfixed> (embed)
1027            - audacity <unfixed> (embed)
1028            - matanza <unfixed> (embed)
1029            - tdom <unfixed> (embed)
1030            - udunits <unfixed> (embed)
1031            - apr-util 1.2 (embed)
1032            - ayttm <unfixed> (embed)
1033            - cableswig <unfixed> (embed)
1034            - cadaver <unfixed> (embed)
1035            - cmake <unfixed> (embed)
1036            - coin3 <unfixed> (embed)
1037            - gdcm <unfixed> (embed)
1038            - ghostscript <unfixed> (embed)
1039            - grmonitor <unfixed> (embed)
1040            - iceape <unfixed> (embed)
1041            - insighttoolkit <unfixed> (embed)
1042            - libparagui1.1 <unfixed> (embed)
1043            - paraview <unfixed> (embed)
1044            - poco <unfixed> (embed)
1045            - simgear <unfixed> (embed)
1046            - sitecopy <unfixed> (embed)
1047            - smart 1.0-1 (embed)
1048            [etch] - smart <unfixed> (embed)
1049            - swish-e <unfixed> (embed)
1050            - tla <unfixed> (embed)
1051            - vtk <unfixed> (embed)
1052            - wbxml2 <unfixed> (embed)
1053            - xmlrpc-c <unfixed> (embed)
1054            - iceweasel <unfixed> (embed)
1055            - kompozer <unfixed> (embed)
1056            - vxl <unfixed> (embed)
1057            - xulrunner <unfixed> (embed)
1058            - apache2 2.2 (embed)
1059            - texlive-bin <unfixed> (embed) [included twice]
1060            - vnc4 <unfixed> (embed)
1061            - xotcl <unfixed> (embed)
1062    
1063    xerces-c
1064            - xerces-c2 <unfixed> (old-version)
1065            - xerces27 <removed> (old-version)
1066    
1067    md5 (RSA's version; not the gnu version provided by coreutils)
1068            - w3c-libwww <removed> (embed; bug #551942)
1069            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1070    
1071    enet
1072            - sauerbraten <unfixed> (embed; #497194)
1073    
1074    eglibc
1075            - glibc <removed> (old-version)
1076    
1077    galib
1078            - gamera 3.2.3-1 (embed)
1079    
1080    configobj
1081            - bzr <unfixed> (embed; bug #555336)
1082            - elisa <unfixed> (embed; bug #555337)
1083            - gaupol <unfixed> (embed; bug #555338)
1084            - ipython <unfixed> (embed; bug #555339)
1085            - pida <unfixed> (embed; bug #555340)
1086            - psychopy <unfixed> (embed; bug #555341)
1087            - rest2web <unfixed> (embed; bug #555342)
1088            - auth2db <unknown> (embed)
1089            - dynagen <unknown> (embed)
1090            - iceweasel <unknown> (embed)
1091            - sabnzbdplus <unknown> (embed)
1092            - xulrunner <unknown> (embed)
1093            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1094    
1095    python-clientform
1096            - bibus <unfixed> (embed; bug #555332)
1097            - zope2.10 <unfixed> (embed; bug #555333)
1098            - zope2.11 <unfixed> (embed; bug #555334)
1099            - python-mechanize <unknown> (embed)
1100            - twill <unknown> (embed)
1101    
1102    python-mechanize
1103            - zope2.10 <unfixed> (embed; bug #555337)
1104            - zope2.11 <unfixed> (embed; bug #555338)
1105            - twill <unknown> (embed; bug #555339)
1106    
1107    pexpect
1108            - duplicity 0.6.06-1 (embed; bug #555361)
1109            - hplip <unfixed> (embed; bug #555362)
1110            - smart <unfixed> (embed; bug #555363)
1111    
1112    pyparsing
1113            - bauble <unfixed> (embed; bug #555366)
1114            - boa-constructor 0.6.1-8 (embed; bug #555367)
1115            - calibre <unfixed> (embed; bug #555368)
1116            - matplotlib <unfixed> (embed; bug #531024)
1117            - zhpy <unfixed> (embed; bug #555370)
1118            - polybori <unknown> (embed)
1119            - python-whoosh <unknown> (embed)
1120            - twill <unknown> (embed)
1121            - zope-textindexng3 <unknown> (embed)
1122    
1123    python-pysqlite2
1124            - python2.4 <unfixed> (embed; bug #553403)
1125            - python2.5 <unfixed> (embed; bug #553403)
1126    
1127    celementtree
1128            - python2.5 <unfixed> (embed)
1129            - smart 1.0-1 (embed)
1130            [etch] - smart <unfixed> (embed)
1131    
1132    elementtree
1133            - python2.5 <unfixed> (embed)
1134            - bzr <unfixed> (embed; bug #555343)
1135            - gedit 2.28.2-1 (embed; bug #555344)
1136            - smart 1.0-1 (embed)
1137            [etch] - smart <unfixed> (embed)
1138            - solfege <unfixed> (embed; bug #555345)
1139            - w3af <unfixed> (embed; bug #555346)
1140            - python-qt4 <unknown> (embed)
1141            - sphinx <unknown> (embed)
1142            - python-nltk <itp> (embed)
1143    
1144    python2.5
1145            - python2.4 <unfixed> (old-version)
1146            - jython <unfixed> (embed)
1147            NOTE: embeds many stdlib modules
1148            - python-django <unfixed> (embed; bug #555419)
1149            NOTE: embeds stdlib modules: doctest, decimal
1150            - gamera 3.2.3-1 (embed)
1151            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1152            - boa-constructor <unfixed> (embed; bug #555426)
1153            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1154            - nicotine <unfixed> (embed; bug #555427)
1155            NOTE: embeds stdlib modules: ConfigParser
1156            - museek+ <unfixed> (embed; bug #555428)
1157            NOTE: embeds stdlib modules: ConfigParser
1158            - vegastrike-data <unfixed> (embed)
1159            NOTE: embeds many stdlib modules
1160            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1161            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1162            - config-manager <unfixed> (embed; bug #555423)
1163            NOTE: embeds stdlib modules: optparse
1164            - jhbuild 2.28.0-1 (embed; bug #555421)
1165            NOTE: embeds stdlib modules: optparse, subprocess
1166            - smart <unfixed> (embed; bug #555432)
1167            NOTE: embeds stdlib modules: optparse
1168            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1169            NOTE: embeds stdlib modules: doctest
1170            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1171            NOTE: embeds stdlib modules: doctest
1172            - distribute <unfixed> (embed)
1173            NOTE: embeds stdlib modules: doctest
1174            - python-setuptools <unfixed> (embed; bug #555435)
1175            NOTE: embeds stdlib modules: doctest
1176            - zope.testing <unfixed> (embed; bug #555436)
1177            NOTE: embeds stdlib modules: doctest
1178            - translate-toolkit <unfixed> (embed; bug #555422)
1179            NOTE: embeds stdlib modules: textwrap, contextlib
1180            - libtpclient-py <unfixed> (embed; bug #555424)
1181            NOTE: embeds stdlib modules: subprocess
1182            - grass <unfixed> (embed; bug #555425)
1183            NOTE: embeds stdlib modules: subprocess
1184            - coherence <unfixed> (embed; bug #555429)
1185            NOTE: embeds stdlib modules: uuid
1186            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1187            NOTE: embeds stdlib modules: uuid
1188            - setroubleshoot <unfixed> (embed; bug #555431)
1189            NOTE: embeds stdlib modules: uuid
1190            - linkchecker <unfixed> (embed; bug #555414)
1191            NOTE: embeds msgfmt.py script
1192            - imdbpy <unfixed> (embed)
1193            NOTE: embeds msgfmt.py script
1194            - kiwi <unfixed> (embed)
1195            NOTE: embeds msgfmt.py script
1196            - moin <unfixed> (embed)
1197            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1198            - plone3 <unfixed> (embed)
1199            NOTE: embeds msgfmt.py script
1200            - roundup <unfixed> (embed)
1201            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1202            - rednotebook <unfixed> (embed; bug #555415)
1203            NOTE: embeds msgfmt.py script
1204            - turbogears <unfixed> (embed)
1205            NOTE: embeds msgfmt.py script
1206            - elisa <unfixed> (embed)
1207            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1208            - calibre <unfixed> (embed)
1209            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1210            - mailman <unfixed> (embed; #555416)
1211            NOTE: embeds msgfmt.py script
1212            - python-docutils <unknown> (embed)
1213            NOTE: embeds stdlib modules: optparse, textwrap
1214            - python-imaging <unknown> (embed)
1215            NOTE: embeds stdlib modules: doctest
1216            - python-mechanize <unknown> (embed)
1217            NOTE: embeds stdlib modules: doctest
1218            - twill <unknown> (embed)
1219            NOTE: embeds stdlib modules: subprocess
1220            - zeroc-ice <unknown> (embed)
1221            NOTE: embeds stdlib modules: subprocess
1222            - wxwidgets2.8 <unknown> (embed)
1223            NOTE: embeds stdlib modules: subprocess
1224            - cycle <unknown> (embed)
1225            NOTE: embeds msgfmt.py script
1226            - deluge <unknown> (embed)
1227            NOTE: embeds msgfmt.py script
1228            - opendict <unknown> (embed)
1229            NOTE: embeds msgfmt.py script
1230            - openerp-client <unknown> (embed)
1231            NOTE: embeds msgfmt.py script
1232            - rapidsvn <unknown> (embed)
1233            NOTE: embeds msgfmt.py script
1234            - wammu <unknown> (embed)
1235            NOTE: embeds msgfmt.py script
1236            - gaphor <unknown> (embed)
1237            NOTE: embeds msgfmt.py script
1238            - pida <unknown> (embed)
1239            NOTE: embeds msgfmt.py script
1240            - python-formencode <unknown> (embed)
1241            NOTE: embeds msgfmt.py script
1242            - duplicity <unfixed> (embed)
1243            NOTE: embeds stdlib module: urlparse, tarfile
1244            - pygopherd <unfixed> (embed)
1245            NOTE: embeds stdlib module: zipfile
1246    
1247    argparse
1248            - twill <unfixed> (embed; bug #555347)
1249            - ipython <unfixed> (embed; bug #555348)
1250    
1251    coherence
1252            - elisa <unfixed> (embed; bug #555335)
1253    
1254    simpletal
1255            - plastex <unfixed> (embed; bug #555371)
1256    
1257    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1258            - postr <unfixed> (embed)
1259            - elisa <unfixed> (embed)
1260    
1261    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1262            - apertium-tolk <unfixed> (embed)
1263            - ipython <unfixed> (embed)
1264            - virtaal <unfixed> (embed)
1265    
1266    distribute
1267            - setuptools <removed> (old-version)
1268    
1269    rails
1270            - jruby1.2 <unfixed> (embed) [./bench/rails/*]
1271            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1272            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1273            - thin <unfixed> (embed) [./spec/rails_app/*]
1274            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1275            NOTE: be dangerous if developers are naively basing their code off of the examples
1276            NOTE: prototype.js is among the example files
1277    
1278    lucene2 (prototype.js is among the embeds in the following)
1279            - lucene <unfixed> (old-version)
1280            - pylucene <unfixed> (embed)
1281            - libpdfbox-java <unfixed> (embed)
1282            - libfontbox-java <unfixed> (embed)
1283            - libjempbox-java <unfixed> (embed)
1284            - solr <unfixed> (embed)
1285    
1286    unicode-data
1287            - syslinux <unfixed> (embed)
1288            - camomile <unfixed> (embed)
1289            - fribidi <unfixed> (embed)
1290            - m17n-db <unfixed> (embed)
1291            - sbcl <unfixed> (embed)
1292            - heimdal <unfixed> (embed)
1293            - icu <unfixed> (embed)
1294            - icu4j <unfixed> (embed)
1295            - krb5 <unfixed> (embed)
1296            - moodle <unfixed> (embed)
1297            - openldap <unfixed> (embed)
1298            - pike7.6 <unfixed> (embed)
1299            - samba <unfixed> (embed)
1300            - samba4 <unfixed> (embed)
1301            - cmucl <unfixed> (embed)
1302            - typo3-src <unfixed> (embed)
1303            - mauve <unfixed> (embed)
1304            - texlive-bin <unfixed> (embed)
1305            - ypsilon <unfixed> (embed)
1306            - jeuclid <unfixed> (embed)
1307            - charmap.app <unfixed> (embed)
1308            - clisp <unfixed> (embed)
1309            - gnulib <unfixed> (embed)
1310            - opensrs-client <unfixed> (embed)
1311            - saxonb <unfixed> (embed)
1312            - rails <unfixed> (embed)
1313    
1314    feedparser
1315            - rawdog <unfixed> (embed; bug #383422)
1316            - miro <unfixed> (embed; bug #555351)
1317            - calibre <unfixed> (embed; bug #555352)
1318            - freevo <unfixed> (embed; bug #555353)
1319            - pida <unfixed> (embed; bug #555354)
1320            - planet-venus <unfixed> (embed; bug #555355)
1321            - plone3 <unfixed> (embed; bug #555356)
1322            - exaile 0.2.14+debian-1 (embed)
1323            - screenlets 0.1.2-3 (embed)
1324            NOTE: included twice
1325    
1326    agg:
1327            - matplotlib <unfixed> (embed: bug #377271)
1328            - contextfree <unfixed> (embed)
1329            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1330            - exactimage <unfixed> (embed)
1331            - python-enable <unfixed> (embed)
1332            - mapnik 0.5.1-3 (embed)
1333            NOTE: links statically to agg, but shared library is not available (bug #377271)
1334    
1335    vtk
1336            - paraview <unfixable> (embed; bug #495426)
1337    
1338    txt2tags
1339            - rednotebook <unfixed> (embed)
1340    
1341    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1342            - gajim <unfixed> (embed)
1343            - emesene <unfixed> (embed)
1344            - convirt <unfixed> (embed)
1345            - pida <unfixed> (embed)
1346            - rednotebook <unfixed> (embed)
1347    
1348    horde3 (prototype.js is among the embeds in the following)
1349            - mnemo2 <unfixed> (embed)
1350            - nag2 <unfixed> (embed)
1351    
1352    cimg
1353            - gmic <itp> (embed)
1354    
1355    mootools
1356            - gmic <itp> (embed)
1357    
1358    openldap
1359            - openldap2.3 <removed> (old-version)
1360    
1361    grub2
1362            - grub <unfixed> (old-version)
1363    
1364    gnupginterface
1365            - duplicity <unfixed> (embed)
1366    
1367    python-dateutil
1368            - awn-extras-applets <unfixed> (embed)
1369            - matplotlib <unknown> (embed)
1370    
1371    cups
1372            - cupsys <removed> (old-version)
1373    
1374    yui
1375            - bcfg2 <not-affected> (present in source but not included in any binary files)
1376            - serendipity <unfixed> (embed; bug #557746)
1377            - moodle 1.8.2.dfsg-5 (embed)
1378            - jifty <unfixed> (embed; bug #557748)
1379            - webgui 7.7.26-1 (embed)
1380            - loggerhead 1.17-1 (embed)
1381    
1382    quake3 (vanilla source not packaged in debian)
1383            - openarena <unfixable> (fork)
1384    
1385    quake2 (vanilla source not packaged in debian)
1386            - alien-arena <unfixable> (fork)
1387            - warsow <unfixable> (fork)

Legend:
Removed from v.4835  
changed lines
  Added in v.13423

  ViewVC Help
Powered by ViewVC 1.1.5