/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 4835 by neilm, Mon Oct 9 20:39:54 2006 UTC revision 15569 by gilbert-guest, Mon Nov 8 02:23:56 2010 UTC
# Line 1  Line 1 
1    Embedded code copies
2    ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects, without linking dynamically:  This is considered bad for fixing security flaws because the fix needs
6    to be applied in multiple source packages.
7  xpdf code: (some use xpdf 2, some xpdf 3)  
8  gpdf (will be replaced by evince in Gnome 2.12)  Format:
9  pdftohtml (current poppler source package has a ported version, pinged maintainer)  <srcpkg> (<optional comment about srcpkg>)
10  kdegraphics/kpdf (upstream is working on using poppler, probably not in time for Etch)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11  tetex-bin (links to poppler since 3.0-12)          NOTE: optional comments about the linkage of the embedding srcpkg
12  cupsys (only older releases, recent ones use xpdf-utils, it's still present in the src, though)  
13  poppler  status: version number fixing the embedded copy
14  koffice (upstream is working on using poppler, probably not in time for Etch)          <unfixed> if the issue is not yet fixed
15  libextractor (uses internal pdf decoder since 0.5.12-1)          <removed> if the package was removed from the archive
16  pdfkit.framework (links to poppler since 0.8-4)          <itp> if the package is in the process of being packaged
17            <not-affected> if the package does not use the embedded copy
18  zlib code: (lots of apps embed a copy, but link dynamically, but there are a few exceptions)          <unknown> if the version number can not be determined
19  dpkg          <unfixable> for unavoidable cases (e.g., forks that add real value)
20  rsync (somehow derived code base)  sort: static (linking statically against a lib)
21  mozilla(?)        embed (embeds a copy of the library into another source package)
22  Linux kernels        modified-embed (embeds a code copy that differs from upstream code)
23  pvpgn (links dynamically since 1.7.8-2)        fork (a full-blown fork of another source package)
24  mrtg (links dynamically since 2.12.2-1)        old-version (an older version of essentially the same code)
   
 libgadu/ekg:  
 centericq  
 gaim  
 kopete (ships the code, but links dynamically in the Debian package)  
 kadu (not packaged in Debian)  
 GNU gadu (not yet packaged in Debian)  
   
   
 xmlrpc: (which package is the "origin" of this code?)  
 drupal  
 phpgroupware  
 egroupware  
 phpwiki  
 php4 (php-pear, IIRC this was reorganized some weeks ago?)  
 tikiwiki (not packaged in Debian)  
   
   
 shtool: (affects build-time only)  
 mysql-ocaml  
 php4  
   
   
 mozilla:  
 mozilla-firefox  
 mozilla-thunderbird  
 nvu  
   
   
 xli:  
 xloadimage  
   
   
 lesstif: (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  
 openmotif  
 xfree86/xorg (in libxpm)  
   
   
 kerberized apps with BSD origin:  
 krb4  
 krb5  
 heimdal  
   
   
 grip: (which pkg is the origin?)  
 libcdaudio  
 grip  
 gnome-vfs (vfs2 as well?)  
   
   
 fudforum:  
 phpgroupware-fudforum  
 egroupware-fudforum  
   
 cvs:  
 gcvs (at least an additional script is included, check if there's more)  
   
 pcre:  
 all pythons  
 php4 (src included, but Debian package links dynamically)  
 analog (src included, but Debian package links dynamically)  
 libgoffice-1  
 tf5 (since 5.0beta7 the Debian package links dynamically)  
   
 tiff:  
 wxpythongtk (check, which debian pkg this is in)  
 older kdegraphics/kpdf releases < 3.3 embedded a copy  
25    
26    The srcpkg might be some string to identify the code if there is no
27    specific source package.
28    
29  uudeview:  Everything up to the next line is ignored.
30  libconvert-uulib-perl  ---BEGIN
31    poppler
32  sqlite: (not affected by security vulnerabilities so far)          - pdftohtml <unknown>
33  amarok          [sarge] - pdftohtml <unfixed>
34            [etch] - pdftohtml <unfixed>
35  util-linux/mount:          NOTE: has been replaced by poppler-utils
36  loop-aes-utils contains code from util-linux' mount in the mount-aes-udeb          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
37            - texlive-base 3.0-12 (embed)
38  webmin:          - texlive-bin 2007-1 (embed)
39  usermin          - koffice 1:2.0.0-1 (embed; bug #436163)
40            - libextractor 0.5.12-1 (embed)
41  sylpheed:          NOTE: libextractor is using its own pdf decoder now
42  sylpheed-claws          - ipe <unfixed> (embed)
43            NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44  phpsysinfo:          - ruby-gnome2 <unknown> (embed)
45  egroupware          - pdfedit <unfixed> (embed; bug #510794)
46  phpgroupware          - swftools <removed> (embed; bug #551293)
47            - xpdf 3.02-9 (fork)
48  phpldapadmin:  
49  egroupware  pdksh (no longer developed since 1999)
50            - mksh <unfixable> (fork)
51  chmlib:          - posh <unfixable> (fork)
52  kchmviewer (not packaged in Debian)  
53    ppmd
54  libavcodec/libavformat:          - libcomplearn-mod-ppmd <unfixed> (fork)
55  ffmpeg          NOTE: discussion in #458152
56  xine-lib  
57  xvidcap (currently in NEW)  libevent
58  kino (links statically, does not include code)          - transmission 1.71-1 (embed; bug #529372)
59  vlc (links statically, does not include code)          - chromium-browser 5.0.375.29~r46008-1
60  smilutils (links statically, does not include code)          - dnsproxy <unknown> (embed)
61  motion (links statically, does not include code)  
62  gst-ffmpeg  lrmi
63  xmovie (currently in NEW)          - read-edid 2.0.0-1 (embed; bug #495131)
64  gst-ffmpeg          - s3switch <unfixed> (embed)
65            - xresprobe <unfixed> (embed)
66  mad MPEG decoding lib:          - zhcon <unfixed> (embed)
67  mad  
68  xine-lib  php-htmlpurifier
69            - mahara 1.2.5-1 (embed)
70            - knowledgeroot 0.9.9.5-5 (embed)
71            - moodle <unfixed> (embed)
72    
73    peercast
74            - gnome-peercast <removed> (embed)
75            [etch] - gnome-peercast <unfixed> (embed)
76    
77    silc-toolkit
78            - silc-client 1.1~beta6-1 (embed)
79    
80    icclib
81            - ghostscript <unfixed> (embed)
82            - argyll <unfixed> (embed)
83    
84    libusb
85            - argyll <unfixed> (embed)
86    
87    dietlibc
88            - ccontrol 0.9.1+20071204-1 (static)
89            - mksh <unfixable> (static)
90            NOTE: /bin/mksh-static only, and only on some arches (others use eglibc)
91    
92    libmikmod
93            - pysol-sound-server <unfixed> (modified-embed)
94            - sdl-mixer1.2 <unfixed> (embed)
95            TODO: report bug
96            - uqm 0.6.2.dfsg-8 (embed)
97            NOTE: Might be fixed earlier. Lenny version recorded.
98            - black-box 1.4.6-2.2 (embed)
99            NOTE: Might be fixed earlier. Lenny version recorded.
100    
101    libiax
102            - iaxmodem <unfixable> (embed; bug #548885)
103    
104    spandsp
105            - iaxmodem <unfixable> (embed; bug #548885)
106    
107    python-paramiko
108            - fabric 0.9.0-2 (embed; bug #561398)
109    
110    zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
111            - dpkg 1.15.6 (static)
112            NOTE: see 18196.48620.491996.624772@davenant.relativity.greenend.org.uk on debian-devel for discussion
113            - rsync <unfixed> (embed)
114            - cherokee <unfixed> (embed)
115            NOTE: somehow derived code base
116            - mono <unfixed> (embed)
117            TODO: check mozilla
118            - Linux kernels <unfixed> (embed)
119            - pvpgn 1.7.8-2 (embed)
120            - mrtg 2.12.2-1 (embed)
121            - rpm <unknown> (embed)
122            NOTE: pinged anibal since when rpm was fixed
123            - tuxcmd-modules <unfixed> (embed)
124            - zsync <unfixed>
125            - tra <unfixed>
126            - sash <unfixed>
127            - nsis <unfixed>
128            - pyfits 1:2.3.1-1
129            - mseide-msegui <unfixed>
130            NOTE: mseide
131            - mirrordir <unfixed>
132            - poco <unfixed>
133            - klibc <unfixed>
134            - emboss <unfixed>
135            - ghostscript <unfixed>
136            - freeimage <unfixed>
137            - clamav <unfixed> (fork)
138            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
139            - tuxonice-userui <unfixed> (static)
140            - plt-scheme <unfixed>
141            - perl <unfixed>
142            - paraview <unfixed>
143            - velvet 0.7.56~nozlibcopy-1
144            - gcvs <unfixed>
145            - dump <unfixed>
146            - aide <unfixed> (static)
147            - dar <unfixed> (static)
148            - avfs <unfixed>
149            - fpc <unfixed>
150            - winff <unfixed>
151            NOTE: inherited from fpc, see #472304
152            - lazarus <unfixed>
153            NOTE: inherited from fpc, see #472304
154            - erlang <unfixed> (embed)
155            - gamera 3.2.3-1 (embed)
156            - python2.4 <unfixed> (embed; bug #553403)
157            - python2.5 <unfixed> (embed; bug #553403)
158            - texlive-bin <unknown> (embed)
159    
160    dulwich
161            - hg-git 0.1.0-1 (embed; bug #541996)
162    
163    libvigraimpex
164            - hugin <unfixed> (embed; bug #542259)
165            - enblend-enfuse <unfixed> (embed; bug #542258)
166            - gamera 3.2.3-1 (embed)
167    
168    libbz2
169            - dpkg 1.15.6 (static)
170            - amd64-libs <unfixed> (static)
171            NOTE: let's call it "static"
172            - dar <unfixed> (static)
173            - dump <unfixed> (static)
174            - unalz 0.64-1 (embed)
175            NOTE: has code, by the maint, to use the system version but links against the internal copy
176            - clamav <unfixed> (embed)
177            NOTE: libclamav/nsis/bzlib*
178            - pristine-tar <unfixable> (modified-embed)
179            NOTE: compression code only, not uncompression
180            - r-base-core-ra 1.2.8 (static)
181            - r-base-core 2.11.1 (static)
182            NOTE: links dynamically in squeeze, statically in lenny
183            - rpm <unfixed> (static)
184            NOTE: lsb-rpm package is statically linked, normal rpm links dynamically
185    
186    libyahoo2
187            - centerim <unfixed> (embed; bug #559783)
188    
189    libmsn
190            - centerim <unfixed> (embed; bug #559783)
191    
192    libgadu
193            - centerim <unfixed> (embed; bug #559783)
194            - pidgin <not-affected> (links dynamically since initial release; fixed in gaim)
195            - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
196            - kdenetwork 4:3.3.2-5 (embed)
197            NOTE: from kdenetwork: kopete
198            - ekg 1:1.8~rc0-1 (embed)
199            - kadu 0.6.0.2-3 (embed; bug #504430)
200            - gadu <itp> (embed)
201    
202    xmlrpc (which package is the "origin" of this code?)
203            - drupal <unfixed> (embed)
204            - phpgroupware <unfixed> (embed)
205            - egroupware <unfixed> (embed)
206            - phpwiki <unfixed> (embed)
207            - php4 <removed> (embed)
208            TODO: check, php-pear, IIRC this was reorganized some weeks ago?
209    
210    shtool (affects build-time only)
211            - mysql-ocaml <unfixed> (embed)
212            - php4 <removed> (embed)
213            - php5 <unfixed> (embed)
214    
215    xulrunner
216            - iceape <unfixed> (embed; bug #561749)
217            - iceweasel 2.0.0.19 (embed)
218            - icedove <unfixed> (embed; bug #561750)
219            - kompozer <unfixed> (embed; bug #532168)
220            - galeon 2.0.2-4 (embed)
221            - epiphany-browser 2.14.3-8 (embed)
222            - conkeror 0.9~git080629-2 (embed)
223            - kazehakase 0.4.2-1 (embed)
224    
225    xli
226            - xloadimage <unfixed> (embed)
227    
228    lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
229            - openmotif <unfixed> (embed)
230    
231    libxpm
232            - lesstif2 <unfixed> (embed; bug #575750)
233    
234    kerberized apps with BSD origin
235            - krb4 <removed> (embed)
236            - krb5 <unfixed> (embed)
237            - heimdal <unfixed> (embed)
238    
239    grip (which pkg is the origin?)
240            - libcdaudio <unfixed>
241            - grip <unfixed>
242            - gnome-vfs <unfixed>
243            TODO: check vfs2 as well
244    
245    fudforum
246            [etch] - phpgroupware <unfixed> (embed)
247            NOTE: phpgroupware-fudforum
248            [sarge] - egroupware-fudforum <removed> (embed)
249    
250    libbsd
251            - rdate 1:1.2-3 (embed)
252            - atheme-services <unfixed>
253            - libbsd-arc4random-perl <not-affected> (modified-embed)
254            NOTE: code not used, it links dynamically against libbsd instead
255            - isakmpd <unfixed>
256            - bsdgames <unfixed> (embed)
257            - bsd-mailx <unfixed> (embed)
258            - netcat-openbsd <unfixed> (embed; bug #550611)
259            - openssh <unfixed> (embed)
260            - unworkable <unfixed> (embed)
261            - mksh <unfixed> (modified-embed)
262            NOTE: strlcpy(), only used in /bin/mksh-static on eglibc arches
263            NOTE: FIXME, we should only have one entry: - mksh <not-affected> (modified-embed)
264            NOTE: strlcpy() on dietlibc arches; {g,s}etmode(); both unused
265    
266    cvs
267            - gcvs <unfixed> (embed)
268            NOTE: see cvsunix/src in tarball
269    
270    pcre3
271            - php4 <removed> (embed)
272            - analog 2:5.23-0woody1 (embed)
273            - chicken 3.2.7-2 (embed)
274            NOTE: Might be fixed earlier. Lenny version recorded.
275            - goffice <unfixed> (embed)
276            NOTE: libgoffice-*
277            - hypermail 2.2.0.dfsg-2 (embed)
278            NOTE: Might be fixed earlier. Lenny version recorded.
279            - privoxy 3.0.9-1 (embed)
280            NOTE: Might be fixed earlier. Lenny version recorded.
281            - vfu 4.06-4.1 (embed; bug #450754)
282            - tf5 5.0beta7-1 (embed)
283            - monotone 0.43-1 (embed)
284            NOTE: this only affects versions >= 0.37
285            - glib2.0 2.15.2-1 (embed)
286            - apache2 2.0.53-4 (embed)
287            - exim4 4.10-0.srh20.12 (embed)
288            - yacas <unfixed> (embed)
289            NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
290            - gtamsanalyzer.app 0.42-5 (embed)
291            - tin 980117-1 (embed)
292            - kazehakase 0.5.2-1
293            - webkit 1.0.1-1 (embed)
294            - qt4-x11 <unfixed> (embed)
295            NOTE: embedded via webkit copy
296            - erlang <unfixed> (embed)
297            - ssed <unfixed> (embed)
298            - ircd-hybrid <unfixed> (static)
299            - emboss <unfixd>
300            - cherokee <unfixed> (embed)
301            - oftc-hybrid 1.6.9.dfsg-1 (embed)
302            - ratbox-services <unfixed> (embed)
303            - squeak-vm <unfixed> (embed)
304            - tinymux <unfixed> (embed)
305    
306    tiff
307            - wxwindows2.4 2.2.1 (embed)
308            - gamera 3.2.3-1 (embed)
309            - freeimage <unfixed> (embed)
310            - libtk-img <unfixed> (embed)
311            NOTE: there are two copies, one under tiff/ other under libtiff/
312            - gdal <unfixed>
313    
314    uudeview
315            - libconvert-uulib-perl <unfixed> (embed)
316            - pan <unfixed> (embed)
317    
318    sqlite (not affected by security vulnerabilities so far)
319            - amarok <unfixed> (embed)
320            - monotone 0.43-1 (embed)
321            - iceweasel <unfixed> (embed)
322            - heimdal <unfixed> (embed; bug #559616)
323    
324    util-linux/mount
325            - loop-aes-utils <unfixed> (embed)
326            NOTE: contains code from util-linux' mount in the mount-aes-udeb
327    
328    sylpheed
329            - sylpheed-claws <unfixed> (fork)
330    
331    phpsysinfo
332            - egroupware <unfixed> (embed)
333            - phpgroupware <unfixed> (embed)
334    
335    phpldapadmin
336            [sarge] - egroupware <unfixed> (embed)
337            NOTE: removed from egroupware after sarge
338    
339    chmlib
340            - kchmviewer <unknown> (embed)
341    
342    ffmpeg (libavcodec/libavformat)
343            - mplayer 1.0~rc2-14 (embed; bug #395252)
344            - kino 1.0.0-1
345            - vlc <not-affected> (Links dynamically since initial release)
346            - smilutils 0.3.0-10
347            NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
348            - motion 3.1.19-1
349            - gstreamer0.10-ffmpeg 0.10.3-2
350            - xmovie <removed> (static)
351            TODO: gimp-gap (potentially using ffmpeg code as well)
352            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
353            - audacity 1.3.7-2 (embed; bug #512278)
354            - chromium-browser <unfixed> (fork)
355    
356    faad2
357            - mplayer 1.0~rc2-20 (embed)
358            - avifile <unfixed> (embed; bug #538750)
359            - ffmpeg-debian <removed> (embed)
360    
361    libmad (MPEG decoding lib)
362            - xine-lib <unfixed> (embed)
363            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
364            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
365    
 libdts:  
366  libdts  libdts
367  xine-lib          - xine-lib <unfixed> (embed)
368    
 flac:  
369  flac  flac
370  xine-lib          - xine-lib <unfixed> (embed)
   
 liba52:  
 a52dec  
 xine-lib  
   
 libmpeg2:  
 mpeg2dec  
 xine-lib  
371    
372  curl:  liba52
373  wget (code for NTLM authentication)          - a52dec <unfixed> (embed)
374            - xine-lib <unfixed> (embed)
375    
376    mpeg2dec (libmpeg2)
377            - xine-lib <unfixed> (embed)
378    
379    libmpeg3
380            - squeak-vm <unfixed> (embed)
381    
382    libntlm
383            - wget <unfixed> (fork; bug #550436)
384            - curl <unfixed> (fork; bug #550437)
385            - cntlm <unfixed> (fork; bug #550438)
386    
387    uw-imap
388            - pine <unfixed> (embed)
389            - alpine <unfixed> (embed)
390    
391    imagemagick
392            - graphicsmagick <unfixed> (fork)
393    
394    python-urlgrabber
395            - mercurial <unfixed> (embed; bug #531062)
396            - w3af <unfixed> (embed; bug #555372)
397            [experimental] - harvestman <unfixed> (embed; bug #555373)
398    
399    beautifulsoup
400            - python-mechanize <unfixed> (embed; bug #555349)
401            - zope2.11 <removed> (embed; bug #555350)
402            - twill <unknown> (embed)
403    
404    halibut
405            - nsis <unfixed> (fork)
406    
407    libghttp
408            - hotway <unfixed> (embed)
409    
410    libsndfile
411            - ardour 1:2.7.1-1 (embed)
412    
413    glibmm2.4
414            - ardour 1:2.7.1-1 (embed)
415    
416    libgnomecanvasmm2.6
417            - ardour 1:2.7.1-1 (embed)
418    
419    libsigc++-2.0
420            - ardour 1:2.7.1-1 (embed)
421    
422    soundtouch
423            - ardour 1:2.7.1-1 (embed)
424    
425    libmms
426            - xine-lib <unfixed> (embed)
427            - mimms <unfixed> (embed)
428    
429    fckeditor
430            - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
431            - moin 1.8.2-2 (embed; bug #452599)
432            - karrigell <removed> (embed; bug #452598)
433            - gforge 4.6.99+svn6225-1 (embed)
434            - request-tracker3.8 <unfixed> (embed)
435            - otrs2 <unfixed> (embed)
436    
437    ipatlas (not packaged in Debian)
438            - moodle <unfixed> (embed; bug #507185)
439    
440    libphp-phpmailer
441            - moodle <unfixed> (embed; bug #507185)
442            - mahara <unfixed> (embed)
443            - symfony <unfixed> (embed; bug #566778)
444            [etch] - phpgroupware <unfixed> (embed)
445            NOTE: phpgroupware-felamimail is only in etch
446            - egroupware <unfixed> (embed; bug #504283)
447            - glpi <unfixed>
448    
449    htmlArea (not packaged in Debian)
450            - moodle <unfixed> (embed)
451    
452    giflib
453            - wine <unfixed> (embed; bug #466181)
454    
455    bennu (not packaged in Debian, http://bennu.sourceforge.net)
456            - moodle <unfixed> (embed)
457    
458    smarty
459            - moodle 1.8.2-2 (embed; bug #471158)
460            - gallery2 2.2.5-2 (embed; bug #471160)
461            - mahara 0.9.2-2 (embed; bug #471201)
462            - gosa 2.4beta1-1 (embed; bug #471200)
463    
464    TinyMCE
465            - wordpress 2.5.1-3 (embed; bug #478257)
466            - moodle <unfixed> (embed; bug #507185)
467            - knowledgeroot <unfixed> (embed)
468            - joomla <itp> (bug #326398)
469            - mahara 1.2.6-1 (embed; #597752)
470    
471    scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
472            - scite <unfixed> (embed)
473            - qscintilla <unfixed> (embed)
474            - qscintilla2 <unfixed> (embed)
475            - geany <unfixed> (fork)
476            - anjuta <unfixed> (embed)
477    
478    libphp-adodb
479            - moodle <unfixed> (embed; bug #507185)
480            NOTE: also AdoDB-XML Schema
481            - gallery2 <unfixed> (embed)
482            - phppgadmin <unfixed> (embed)
483            - egroupware <unfixed> (embed)
484            - phpwiki <unfixed> (embed)
485            - torrentflux 2.0beta1-2 (embed)
486            - ipplan <unfixed> (embed)
487            - typo3-src <unfixed> (embed)
488            - cacti <unknown> (embed)
489            [sarge] - cacti <unfixed> (embed)
490            NOTE: dependency exists, but internal version is used
491            - gforge 4.7~rc2-6 (embed)
492            - mahara <unfixed> (embed)
493    
494    gzip
495            - linux-2.6 <unfixed> (embed) [lib/inflate.c]
496            - klibc <unfixed> (embed)
497            NOTE: based on linux-kernel gzip code
498            - busybox <unfixed> (embed)
499            - pristine-tar <unfixed> (modified-embed)
500            NOTE: compression code only, not uncompression
501            - ncompress <unfixed> (old-version)
502    
503    neon
504            - cadaver 0.22.3+debian-1 (embed; bug #188381)
505            - gnome-vfs2 <unfixed> (embed; bug #395874)
506            [etch] - litmus <unfixed> (embed; #395875)
507            - litmus <removed> (embed; #395875)
508            [sarge] - screem <unfixed> (embed)
509            - sitecopy 1:0.16.0-1 (embed; bug #395876)
510            [etch] - tla <unfixed> (embed; bug #395877)
511            [sarge] - tla <unfixed> (embed; bug #395877)
512    
513    libmodplug
514            - gst-plugins-bad0.10 0.10.10.2-1 (embed)
515    
516    libvncserver
517            - vino <unfixed> (embed)
518    
519    putty
520            - filezilla <unfixed> (embed)
521    
522    tinyxml (not packaged in Debian; itp bug #531968)
523            - filezilla <unfixed>
524            - crystalspace <unfixed> (embed)
525            - libwfut <unfixed> (embed)
526            - rarian <unfixed> (embed)
527            - bulletml <unfixed> (embed)
528            - pokerth <unfixed> (embed)
529            - qutecom <unfixed> (embed)
530            - sofa-framework <unfixed> (embed)
531            - yate <unfixed> (embed)
532            - antigrav <unfixed> (embed)
533            - balder2d <unfixed> (embed)
534            - cal3d <unfixed> (embed)
535            - criticalmass <unfixed> (embed)
536            - ember <unfixed> (embed)
537            - epiphany <unfixed> (embed)
538            - gambit <unfixed> (embed)
539            - noiz2sa <unfixed> (embed)
540            - ogre <unfixed> (embed)
541            - opencity <unfixed> (embed)
542            - openmovieeditor <unfixed> (embed)
543            - pouetchess <unfixed> (embed)
544            - tecnoballz <unfixed> (embed)
545            - trigger-rally <unfixed> (embed)
546            - xmoto <unfixed> (embed)
547            - mapnik <unknown> (embed)
548            NOTE: uses a different XML parser by default
549            - rrootage 0.23a-6 <embed>
550            NOTE: links to libbulltetml
551            - boson <unknown> (embed)
552            NOTE: the embedded code is unused
553    
554    gv
555            - evince <unfixed> (embed)
556            NOTE: ps/ tree from gv 3.5.8
557            NOTE: evince-gtk is affected (a component of evince source package)
558    
559    libXbae
560            - paw <unfixed> (embed)
561    
562    libgtkhtml
563            - claws-mail-extra-plugins <unfixed> (fork)
564    
565    libXaw
566            - paw <unfixed> (embed)
567            NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
568    
569    libgd2
570            - graphviz <unfixed> (embed)
571            NOTE: lib/gd seems to be 2.0.33
572            - wml 2.0.11ds2-1 (embed)
573            - libwmf <unfixed> (embed)
574            NOTE: derived from gd 1.6.3
575            - plt-scheme <unfixed> (embed; bug #601525)
576            - texlive-bin 2009-1 (embed)
577    
578    rar
579            - unrar-nonfree <unfixed> (embed)
580    
581    unrar-free (maybe this code is derived from the original rar, too?)
582            - clamav <unfixed> (embed)
583            NOTE: seems to be disabled in default config
584    
585    mplayer (DirectMedia Object loader)
586            - xine-lib <unfixed> (embed)
587            NOTE: src/libw32dll/
588            - vlc <unfixed> (embed)
589            NOTE: modules/codec/dmo/
590            - mplayer 1.0~rc2-20 (embed)
591    
592    libwpd (WordPerfect converter)
593            - openoffice.org <unfixed> (embed)
594    
595    fsplib (http://sourceforge.net/projects/fsp/)
596            - gftp <unfixed> (embed)
597            NOTE: lib/fsplib version 0.3
598    
599    sprng
600            - tree-puzzle <unfixed> (embed)
601    
602    librpcsecgss
603            - krb5 <unfixed> (embed)
604    
605    jasper
606            - ghostscript 8.64~dfsg-2 (embed)
607    
608    libiris
609            - psi <unfixed> (embed)
610            - kdenetwork <unfixed> (embed)
611            NOTE: kopete embeds libiris but links dynamically to libidn
612            - kdegames <unfixed> (embed)
613            NOTE: ksirk/kde4
614    
615    libidn
616            - monotone 0.43-1 (embed)
617            - psi <unfixed> (embed)
618            NOTE: psi embeds libiris which embeds libidn
619            - kdegames <unfixed> (embed)
620            NOTE: kdegames/kde4 embeds libiris which embeds libidn
621    
622    lua5.1
623            - monotone 0.43-1 (embed)
624            - nmap 5.00-1 (embed; bug #527997)
625            [lenny] - nmap <unfixed> (embed; bug #527997)
626            - ocropus <unfixed> (embed)
627            - enigma <unfixed> (embed)
628            NOTE: requires lua built with C++
629            - freeciv <unfixed> (embed)
630            - spring <unfixed> (embed)
631    
632    libbotan
633            - monotone 0.43-1 (embed)
634    
635    NetXX
636            - monotone 0.43-1 (embed)
637    
638    libgc
639            - mono <unfixed> (embed)
640    
641    lzma
642            - p7zip <unfixed> (embed)
643            - xz-utils <unfixed> (fork)
644            - r-base <unfixed> (embed)
645            NOTE: lzma support not yet in lenny or in r-base-core-ra 1.2.8
646    
647    lzo
648            - grub2 <unfixed> (embed)
649    
650    yassl
651            - mysql-dfsg-5.0 <unfixed> (embed)
652            - mysql-5.1 <unfixed> (embed)
653    
654    pax code
655            - tar <unfixed> (embed)
656            - cpio <unfixed> (embed)
657    
658    t1lib
659            - tetex-bin 2.0.2-1 (embed)
660            - texlive-bin <unknown> (embed)
661            - grace 5.1.14-2 (embed)
662            NOTE: Might be fixed even earlier
663    
664    guichan
665            - boswars <unfixed> (embed)
666            NOTE: maintainer notified us, working on it
667    
668    tolua
669            - boswars <unfixed> (embed)
670            NOTE: maintainer notified us, working on it
671            NOTE: actually tolua++
672            - ocropus <unfixed> (embed)
673            NOTE: actually tolua++
674            - freeciv <unfixed> (embed)
675            NOTE: actually tolua++
676            - enigma <unfixed> (embed)
677    
678  TODO evaluate:  asio-dev
679  gimp-gap (potentially using ffmpeg code as well)          - luxrender <removed> (embed)
680    
681  uw-imap:  xine-lib
682  pine          - vlc <unfixed> (embed)
683            NOTE: only parts included in modules/access/rtsp
684    
685  imagemagick:  netpbm
686  graphicsmagick          - tcl8.3 <unfixed> (embed)
687            - tcl8.4 <unfixed> (embed)
688            - tcl8.5 <unfixed> (embed)
689            NOTE: generic/tkImgGIF.c
690    
691    tk8.5
692            - tk8.0 <removed> (old-version)
693            - tk8.3 <unfixed> (old-version)
694            - tk8.4 <unfixed> (old-version)
695            - perl-tk <unfixable> (fork)
696    
697    samba
698            - mc 2:4.6.2~git20080311-1 (embed)
699            NOTE: maintainer is aware of this, currently searching a solution
700    
701    plib1.8.4c2
702            - boson <unfixed> (fork)
703            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
704    
705    fribidi
706            - quesoglc 0.7.2-2 (embed)
707    
708    glew
709            - quesoglc <unfixed> (embed; bug #489341)
710            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
711            - trigger 0.5.2.1-2 (embed)
712            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
713            - trigger-rally 0.5.2.1-2 (embed)
714            NOTE: http://lists.debian.org/debian-devel-games/2009/12/msg00007.html
715            - chromium-browser 5.0.375.70~r48679-2
716    
717    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
718            - transcend <unfixed> (embed)
719            - cultivation <unfixed> (embed)
720            - passage <unfixed> (embed)
721            - gravitation <unfixed> (embed)
722    
723    tar
724            - libarchive <unfixed> (embed)
725            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
726    
727    cpio
728            - libarchive <unfixed> (embed)
729            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
730    
731    kde4libs
732            - kdelibs <unfixable> (old-version)
733    
734    webkit
735            - qt4-x11 <unfixed> (embed; bug #479851)
736            [etch] - qt4-x11 <not-affected> (webkit support introduced in version 4.4)
737            - kde4libs <unfixable> (fork)
738            NOTE: kde4lib's khtml and webkit were forked from khtml (this tracking, which seems
739            NOTE: reversed genesis-wise, is used because of so much other stuff in kde4libs)
740            - chromium-browser <unfixed> (fork)
741    
742    ftgl
743            - blender 2.46+dfsg-1 (embed)
744    
745    wv
746            - abiword <unfixed>
747    
748    qemu
749            - kvm <removed> (embed; bug #543159)
750            - qemu-kvm <unfixed> (embed; bug #560853)
751            NOTE: kvm superceded by qemu-kvm, which is just user interface (no modules)
752            - xen-3 3.4.2-2 (embed; bug #560856)
753            - xen-unstable <unfixed> (embed; bug #560856)
754    
755    vgabios
756            - kvm <removed> (embed; bug #489442)
757            - qemu-kvm <unfixed> (embed)
758    
759    bochs
760            - kvm <removed> (embed; bug #489442)
761            - qemu-kvm <unfixed> (embed)
762    
763    speex
764            - vorbis-tools <unfixed> (embed)
765            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
766            - gst-plugins-good0.10 <unfixed> (embed)
767            - xine-lib <unfixed> (embed)
768            - libfishsound <unfixed> (embed)
769            - libannodex <removed> (embed)
770            - opal 3.4.2~dfsg-2 (embed)
771            - mumble 1.2.0~beta1-1 (embed)
772            - vlc <unfixed> (embed)
773            - xmms-speex <unfixed> (embed)
774            - libsdl-sound1.2 <unfixed> (embed)
775            - sweep <unfixed> (embed)
776    
777    libreadline
778            - magic <itp> (old-version)
779    
780    opcode
781            - ode <unfixed> (embed)
782            NOTE: opcode is not a package in debian, it is just embedded
783            NOTE: http://www.codercorner.com/Opcode.htm
784    
785    gimpact
786            - ode <unfixed> (embed)
787            NOTE: gimpact is not a package in debian, it is just embedded
788            NOTE: http://gimpact.sf.net
789    
790    mochikit
791            - mahara <unfixed> (embed)
792            NOTE: they require extra patches, still unmerged upstream
793            - ntop <unfixed> (embed)
794            - coherence 0.6.2-1 (embed)
795            - paste <unfixed> (embed)
796            - turbogears <unfixed> (embed)
797            - plone3 <removed> (embed)
798            - xulrunner <unfixed> (embed)
799            - libjifty-plugin-chart-perl <unfixed> (embed)
800            - sabnzbdplus <unfixed> (embed)
801            - tgmochikit <unfixed> (embed)
802    
803    prototypejs
804            - netbeans-ide 6.0.1+dfsg-2 (embed)
805            - auth2db 0.2.5-2+dfsg-1 (embed; bug #555218)
806            - webcit <unfixed> (embed; bug #555219)
807            - asterisk 1:1.6.2.0~rc3-1 (embed)
808            - libjson-ruby 1.1.4-1 (embed; bug #555224)
809            - lucene2 2.9.1+ds1-2 (embed; bug #555226)
810            - horde3 <unfixed> (embed)
811            - knowledgeroot 0.9.8.5-4 (embed; bug #555230)
812            - mediatomb 0.12.0~svn2018-5 (embed; bug #555233)
813            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
814            - ebug-http <unfixed> (embed; bug #555236)
815            - libaws 2.7-1 (embed; bug #555222)
816            - phpgedview <removed> (embed)
817            - poker-network 1.7.6-1 (embed; bug #555238)
818            - rails 2.1.0-6 (embed)
819            - wordpress 2.5.0-2 (embed; bug #555243)
820            - zope <not-affected> (the prototypejs embed is not in any of the obvious zope packages, e.g. zope2.9, zope2.10, zope2.11, and zope3)
821            TODO: search through all of the other zope packages
822            - ampache 3.4.1-2 (embed)
823            - exaile 0.2.14+debian-2.1 (embed; bug #555245)
824            - hobix 0.5~svn20070319-4 (embed; bug #555247)
825            - zabbix 1.6.6-4 (embed; bug #555250)
826            - chora2 2.1.1+debian0-1 (embed; bug #555253)
827            - gollem 1.1.1+debian0-1 (embed; bug # 555254)
828            - jscropperui 1.2.1-1 (embed; bug #555257)
829            - scriptaculous <not-affected> (uses system prototype.js since initial upload; bug #555260)
830            - ingo1 1.2.3+debian0-1 (embed; bug #555261)
831            - kronolith2 2.3.3+debian0-1 (embed; bug #555262)
832            - activeldap 1.2.1-1 (embed)
833            - libv8 <not-affected> (contains a google-specific implementation of prototype.js)
834            - mantis 1.1.2+dfsg-1 (embed; bug #555265)
835            - otrs2 2.3.4-6 (embed; bug #555267)
836            - webcalendar 1.2~b1-2 (embed; bug #555269)
837            - redmine 0.9.0~svn2907-1 (embed; bug #555270)
838            - jifty 0.90519-1 (embed; bug #555271)
839            - jquery 1.4-1 (embed; bug #555272)
840            - passenger 2.2.5debian1-1 (embed; bug #555273)
841            - plone3 <removed> (embed; bug #555275)
842            - wesnoth <not-affected> (prototype.js not included in any of the binary packages; bug #555277)
843            - libhtml-prototype-perl 1.48-3 (embed; bug #538920)
844            - xulrunner <unfixed> (embed)
845            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
846            - jclicmoodle <unfixed> (embed)
847            - git-cola <unfixed> (embed)
848    
849    gdb
850            - insight <unfixed> (embed)
851    
852    e2fsprogs
853            - ldiskfsprogs <unfixable> (fork)
854    
855    quazip (not packaged in Debian)
856            - qcake <unfixed> (embed)
857            NOTE: starting with upstream version 0.6.4
858    
859    exo
860            - pcmanfm <unfixed> (embed; bug #499677)
861            NOTE: slightly modified source code
862    
863    java
864            - openjdk-6 <unfixed>
865            - sun-java5 <unfixed>
866            - sun-java6 <unfixed>
867    
868    libphp-snoopy
869            - ampache 3.4.1-2 (embed; bug #504169)
870            - gforge 4.6.99+svn6094-2 (embed)
871            - mahara 1.0.5-2 (embed; bug #504170)
872            - pixelpost 1.7.1-5 (embed; bug #504171)
873            - mediamate 0.9.3.6-5 (embed; bug #504172)
874            - opendb <removed> (embed; bug #504173)
875            [etch] - opendb <unfixed> (embed; bug #504173)
876            - wordpress 2.5.1-9 (embed; bug #443948)
877            - moodle <unfixed> (embed; bug #507185)
878            [etch] - phpgroupware <unfixed> (embed)
879            NOTE: phpgroupware-felamimail
880            - magpierss 0.72-3 (embed; bug #431089)
881    
882    jquery
883            - zekr <unfixed> (embed)
884            - wordpress <unknown> (embed)
885            - yocto-reader <unfixed> (embed)
886            - textpattern <unfixed> (embed)
887            - genshi 0.5.1-1 (embed)
888            NOTE: compressed file under examples/ dir
889            - prewikka <unfixed> (embed)
890            - libramaze-ruby <unfixed> (embed)
891            - drupal6 <unfixed> (embed)
892            - b2evolution <unfixed> (embed)
893            - wesnoth <unfixed> (embed)
894    
895    tablesorter (jquery plugin, not packaged yet)
896            - wesnoth <unfixed> (embed)
897    
898    kses
899            - wordpress <unfixed> (embed; bug #504242)
900            NOTE: their copy has all methods renamed to wp_<foo>
901            NOTE: kses isn't in Debian, RFP: #504240
902            - moodle <unfixed> (embed; bug #507185)
903            - egroupware <unfixed> (embed)
904    
905    magpierss
906            - wordpress <unfixed> (embed; bug #504242)
907            - moodle <unfixed>
908    
909    php-gettext
910            - wordpress 2.8.4-1 (embed; bug #504242)
911            - docbookwiki <unfixed> (embed)
912            - knowledgeroot 0.9.9.5-1
913            NOTE: non-free
914    
915    libphp-ixr (name may change, it is the Incutio XML-RPC)
916            - wordpress <unfixed> (embed; bug #504242)
917            NOTE: libphp-ixr isn't in Debian, RFP: #504236
918            - dokuwiki <unfixed> (embed)
919            - textpattern <unfixed> (embed)
920    
921    libphp-cas
922            - glpi <unfixed> (embed)
923            - moodle <unfixed> (embed; bug #505984)
924    
925    scriptaculous (prototype.js is among the embeds in the following)
926            - glpi <unfixed> (embed)
927            - libaws <unfixed> (embed; bug #555222)
928            - op-panel <unfixed> (embed)
929            - symfony <unfixed> (embed)
930            NOTE: maintainer says there are extra incompatible changes required
931            - pixelpost 1.7.1-6 (embed)
932            - webhelpers <unfixed> (embed)
933            - qwik <removed> (embed; bug #555241)
934            - smokeping <unfixed> (embed)
935            - turba2 <unfixed> (embed)
936            - typo3-src 4.2.3-1 (embed)
937            - request-tracker3.6 <unfixed> (embed)
938            - request-tracker3.8 <unfixed> (embed)
939            - rt-extension-emailcompletion <not-affected> (prototype.js not included in the binary package)
940            - wordpress 2.5.0-2 (embed)
941            - libhtml-prototype-perl 1.48-3 (embed)
942    
943    libmarkdown-php
944            - moodle <unfixed> (embed; bug #507185)
945            - pixelpost 1.7.1-6 (embed)
946    
947    php-openid
948            - wordpress-openid 3.3.2-1 (embed)
949    
950    geshi
951            - dokuwiki 0.0.20080505-3.1 (embed)
952            - pgfouine 1.0-1.1 (embed)
953            - websvn 2.1.0-1 (embed)
954    
955    webcalendar
956            - gforge 4.7~rc2-6 (embed; bug #504758)
957    
958    libical
959            - kdepim <unknown> (fork)
960            NOTE: fixed at some point during 4.0
961            - kdepimlibs 4.2.0-1 (fork)
962            - claws-mail-extra-plugins <unfixed> (fork)
963    
964    harfbuzz
965            - qt4-x11 <unfixed> (embed)
966            - pango1.0 <unfixed> (embed)
967            - fontmatrix <unfixed> (embed)
968    
969    libzip
970            - php5 <unfixable> (modified-embed)
971            - odt2txt <unfixed> (embed; bug #523808)
972    
973    json.php (not packaged; should be replaced with php's built-in functions)
974            - moodle <unfixed>
975            - yui <unfixed>
976            - gallery2 <unfixed>
977            - dokuwiki <unfixed>
978            - typo3-src <unfixed>
979    
980    php-fpdf
981            - tcpdf <itp> (fork)
982            - moodle <unfixed>
983            - phpwiki <unfixed>
984            - egroupware <unfixed>
985            - ldap-account-manager <unfixed> (fork)
986    
987    tcpdf (itp: #495985)
988            - moodle <unfixed>
989            - phpmyadmin <unfixed>
990    
991    typo3
992            - moodle <unfixed>
993    
994    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
995            - moodle <unfixed>
996            - gosa <unfixed>
997    
998    php-ole (itp: #487558)
999            - moodle <unfixed>
1000    
1001    pieforms (http://www.catalyst.net.nz)
1002            - mahara <unfixed>
1003    
1004    savant2 (http://phpsavant.com)
1005            - egroupware <unfixed>
1006    
1007    rssparser (http://nwow.org)
1008            - egroupware <unfixed>
1009            - phpgroupware <unfixed>
1010    
1011    lcms
1012            - openjdk-6 <unfixed> (fork)
1013            - gimp 2.4.0~rc2-2
1014    
1015    libphp-phplayersmenu
1016            - diogenes <unfixed>
1017            - phpldapadmin <unfixed>
1018    
1019    libphp-pclzip
1020            - docvert <unfixed>
1021            - moodle <unfixed>
1022            - egroupware <unfixed>
1023    
1024    libphp-simplepie
1025            - dokuwiki <unfixed>
1026            - wordpress <unfixed>
1027    
1028    libphp-jpgraph
1029            - egroupware <unfixed>
1030    
1031    php-simpletest
1032            - moodle <unfixed>
1033    
1034    libpng
1035            - doxygen 1.5.6-2 (embed)
1036            NOTE: Might be fixed earlier. Lenny version recorded.
1037            - gdal 1.5.2-3 (embed)
1038            NOTE: Might be fixed earlier. Lenny version recorded.
1039            - iceweasel <not-affected> (uses xulrunner)
1040            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
1041            - iceape 1.0.13~pre080614i-0etch1 (embed)
1042            - libfltk1.1 1.1.9-6 (embed)
1043            NOTE: Might be fixed earlier. Lenny version recorded.
1044            - libtk-img <unfixed> (embed)
1045            - htmldoc 1.8.27-3 (embed)
1046            NOTE: Might be fixed earlier. Lenny version recorded.
1047            - xulrunner 1.9.0.13-1 (embed)
1048            [lenny] - xulrunner 1.9.0.11-0lenny1
1049            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1050            - gamera 3.2.3-1 (embed)
1051            - freeimage <unfixed> (embed)
1052            - syslinux-common <unfixable> (embed)
1053            - tuxonice-userui <unfixed> (static)
1054            - texlive-bin 2007.dfsg.2-1~lenny2 (embed)
1055            NOTE: Might be fixed earlier. Lenny version recorded.
1056            - vice 1.22.dfsg1-0.1 (embed)
1057            NOTE: Might be fixed earlier. Lenny version recorded.
1058            - visualboyadvance 1.8.0-4 (embed)
1059            NOTE: Might be fixed earlier. Lenny version recorded.
1060    
1061    irssi
1062            - silc-client <unfixed> (embed)
1063            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
1064    
1065    extc
1066            - mtasc <unfixed> (embed)
1067            - haxe <unfixed> (embed)
1068    
1069    swflib
1070            - mtasc <unfixed> (embed)
1071            - haxe <unfixed> (embed)
1072    
1073    libitext-java
1074            - bouncycastle 2.1.4-1 (embed)
1075    
1076    python-ply
1077            - pyke <unfixed> (embed; bug #555363)
1078            - pywbem 0.7.0-4 (embed; bug #555364)
1079            - sepolgen <unfixed> (embed; bug #555365)
1080            - zope-textindexng3 <unknown> (embed)
1081            - iceweasel <not-affected> (uses xulrunner)
1082            - xulrunner <unknown> (embed)
1083            - wireshark <not-affected> (python-ply modules are not installed into binary packages; see #554613)
1084    
1085    libdumbnet (libdnet upstream)
1086            - nmap <unfixed> (fork)
1087    
1088    gcc-4.4
1089            - gcc-mingw32 <unfixed> (embed)
1090    
1091    camlimages
1092            - advi <unfixed> (static; bug #550441)
1093    
1094    memcached
1095            - memcachedb <unfixed> (embed)
1096    
1097    yajl
1098            - argyll <unfixed> (embed; bug #544223)
1099            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
1100    
1101    nusoap
1102            - gforge 4.8.2-1 (embed)
1103            - ampache <unfixed> (embed)
1104            - poker-network <unfixed> (embed)
1105            - moodle <unfixed> (embed)
1106            NOTE: code is not used when running under php5 and soap is enabled
1107            - phpwiki <unfixed> (embed)
1108            - gallery2 <unfixed> (embed)
1109            - typo3-src <unfixed> (embed)
1110            - phpgacl 3.3.7-7 (embed)
1111            - mantis 1.1.8+dfsg-1 (embed)
1112    
1113    libept
1114            - adept <unfixed> (embed; bug #540649)
1115    
1116    libvorbis
1117            - iceweasel <not-affected> (uses xulrunner)
1118            - xulrunner <unfixed> (embed; bug #540959)
1119            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1120            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1121            - iceape <unfixed> (embed)
1122            [etch] - iceape <not-affected> (introduced in 2.0)
1123            [lenny] - iceape <not-affected> (introduced in 2.0)
1124    
1125    cairo
1126            - iceweasel <not-affected> (uses xulrunner)
1127            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
1128    
1129    liboggz
1130            - iceweasel <not-affected> (uses xulrunner)
1131            - xulrunner <unfixed> (embed; bug #540959)
1132            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1133            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1134            - iceape <unfixed> (embed)
1135            [etch] - iceape <not-affected> (introduced in 2.0)
1136            [lenny] - iceape <not-affected> (introduced in 2.0)
1137    
1138    liboggplay
1139            - iceweasel <not-affected> (uses xulrunner)
1140            - xulrunner <unfixed> (embed; bug #540959)
1141            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1142            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1143            - iceape <unfixed> (embed)
1144            [etch] - iceape <not-affected> (introduced in 2.0)
1145            [lenny] - iceape <not-affected> (introduced in 2.0)
1146    
1147    php-net-dnsbl
1148            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1149    
1150    php-onyx-rss
1151            - serendipity <unfixed> (embed; bug #541740; wontfix: only one script, own package is overkill, appears not to be duplicated in Debian)
1152    
1153    php-text-wiki
1154            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1155    
1156    php-xml-rpc
1157            - serendipity <unfixed> (embed; bug #541740; package in NEW)
1158    
1159    polarssl (does not have a shared library)
1160            - pdkim <itp> (embed; bug #543150)
1161            - xyssl <unfixed> (old-version)
1162    
1163    pidgin (libpurple)
1164            - gaim <removed> (old-version)
1165            - qutecom 2.2~rc3.hg396~dfsg1-6 (embed; bug #559785)
1166            - wengophone <unfixed> (embed; bug #601425)
1167    
1168    icu
1169            - webkit 1.0.1-1 (embed; bug #547214)
1170            - texlive-bin <unfixed> (fork)
1171            NOTE: texlive upstream working with icu upstream to merge their changes
1172            - chromium-browser 5.0.375.29~r46008-3
1173    
1174    cyrus-imapd-2.2
1175            - kolab-cyrus-imapd <unfixed> (fork)
1176            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
1177    
1178    python-cxx-dev
1179            - freecad 0.9.2646.3-1 (embed; bug #547936)
1180    
1181    zipios++
1182            - freecad 0.9.2646.3-1 (embed; bug #547941)
1183            - enigma 0.92.3-3 (embed)
1184            NOTE: likely fixed earlier, marking etch's version as fixed
1185    
1186    linux-2.6
1187            - kvm <removed> (embed; bug #549973) [./kernel/*]
1188            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
1189            - kernel-source-2.6.8 <removed> (old-version)
1190            - kernel-source-2.4.27 <removed> (old-version)
1191            - kernel-source-2.4.24 <removed> (old-version)
1192            - kernel-source-2.2.25 <removed> (old-version)
1193            - kernel-source-2.2.20 <removed> (old-version)
1194    
1195    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1196            - kvm <removed> (embed) [./libfdt/*]
1197            - qemu-kvm <unfixed> (embed) [./libfdt/*]
1198    
1199    qweb (not packaged)
1200            - ajaxterm <unfixed>
1201    
1202    opensaml2
1203            - opensaml <removed> (old-version)
1204    
1205    shibboleth-sp2
1206            - shibboleth-sp <removed> (old-version)
1207    
1208    tuxonice-userui
1209            - suspend2-userui <removed> (old-version)
1210    
1211    expat
1212            - w3c-libwww <removed> (embed; bug #551941)
1213            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1214            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1215            - python2.5 <unfixable> (embed; bug #553403) [./Modules/expat/*]
1216            - python2.4 <unfixable> (embed; bug #553403)
1217            - python2.7 2.7-6 (embed)
1218            - mcabber 0.10.0-1 (low; bug #601053)
1219            - python-4suite <unfixed> (embed; bug #516935)
1220            - wxwindows2.4 <removed> (embed)
1221            - wxwidgets2.6 2.6.3.2.2-4 (embed)
1222            - wxwidgets2.8 2.8.10.1-2 (embed)
1223            - albert <unfixed> (embed; bug #600974)
1224            - celementtree 1.0.5-8 (embed)
1225            NOTE: Maybe that was fixed even earlier
1226            - centerim <unfixed> (embed; bug #559783)
1227            - audacity 1.3.2-1 (embed)
1228            - matanza <unfixed> (embed)
1229            - tdom 0.8.3~20080525-1 (embed)
1230            - udunits 2.1.8-4 (embed)
1231            - apr-util 1.2 (embed)
1232            - ayttm <unfxed> (embed; bug #561006)
1233            - cableswig <unfixed> (embed)
1234            - cadaver <unfixed> (embed)
1235            - cmake 2.6.0-6 (embed)
1236            - coin3 <unfixed> (embed)
1237            - cvsnt 2.5.03.2382-3.3+lenny1 (embed)
1238            NOTE: Might be fixed earlier. Lenny version recorded.
1239            - dasher 4.7.3-1 (embed)
1240            NOTE: Might be fixed earlier. Lenny version recorded.
1241            - gdcm 2.0.14-2 (embed)
1242            - ghostscript 8.71~dfsg-2 (embed)
1243            - grmonitor <removed> (embed)
1244            - iceape <unfixed> (embed)
1245            - insighttoolkit 3.16.0-1 (embed)
1246            NOTE: insighttoolkit might've been fixed earlier
1247            - jabber 1.4.3-3.4 (embed)
1248            NOTE: Might be fixed earlier. Lenny version recorded.
1249            - libparagui1.1 1.0.2-1 (embed)
1250            - libspiff1 0.8.3-1 (embed)
1251            NOTE: Might be fixed earlier. Lenny version recorded.
1252            - mcabber <unfixed> (embed; bug #601053)
1253            - paraview 3.6.2-1 (embed)
1254            - poco 1.3.6p1-1 (embed)
1255            - scorched3d 41.3dfsg-1+b1 (embed)
1256            NOTE: Might be fixed earlier. Lenny version recorded.
1257            - simgear <unfixed> (embed)
1258            - sitecopy 1:0.16.0-1
1259            - smart <unfixed> (embed)
1260            NOTE: smart embeds celementree, and it includes expat
1261            - swish-e <not-affected> (Linked against libxml, which is used instead)
1262            - tla 1.3.5+dfsg-15 (embed)
1263            - vtk 4.1.20030227-1 (embed)
1264            - wbxml2 <not-affected> (expat code is only used on Mac OS X, see #560941)
1265            - xmlrpc-c <unfixed> (embed)
1266            - iceweasel <unfixed> (embed)
1267            - kompozer <unfixed> (embed)
1268            - vxl 1.13.0-2 (embed)
1269            - xulrunner <unfixed> (embed)
1270            - xmame 0.106-2.1 (embed)
1271            NOTE: Might be fixed earlier. Lenny version recorded.
1272            - apache2 2.2 (embed)
1273            - texlive-bin <not-affected> (Embedded code not compiled in)
1274            - vnc4 <unfixed> (embed)
1275            - xotcl 1.6.6-1 (embed)
1276            - chromium-browser 5.0.375.29~r46008-3
1277    
1278    xerces-c
1279            - xerces-c2 <unfixed> (old-version)
1280            - xerces27 <removed> (old-version)
1281    
1282    md5 (RSA's version; not the gnu version provided by coreutils)
1283            - w3c-libwww <removed> (embed; bug #551942)
1284            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1285    
1286    libparagui1.1
1287            - asc <unfixable> (fork)
1288    
1289    enet
1290            - sauerbraten <unfixed> (embed; #497194)
1291    
1292    eglibc
1293            - glibc <removed> (old-version)
1294            - mksh <unfixable> (static)
1295              NOTE: /bin/mksh-static only, and only on some arches (others use dietlibc)
1296    
1297    galib
1298            - gamera 3.2.3-1 (embed)
1299    
1300    configobj
1301            - bzr 2.1.0~rc2-1 (embed; bug #555336)
1302            - elisa <unfixed> (embed; bug #555337)
1303            - gaupol <unfixed> (embed; bug #555338)
1304            - ipython <unfixed> (embed; bug #555339)
1305            - pida <unfixed> (embed; bug #555340)
1306            - psychopy <unfixed> (embed; bug #555341)
1307            - rest2web <unfixed> (embed; bug #555342)
1308            - auth2db <unknown> (embed)
1309            - dynagen <unknown> (embed)
1310            - iceweasel <unknown> (embed)
1311            - sabnzbdplus <unknown> (embed)
1312            - xulrunner <unknown> (embed)
1313            - nipy <not-affected> (part of an example [/examples/neurospin/neurospy/configobj.py], which is not installed into binary packages)
1314    
1315    python-clientform
1316            - bibus <unfixed> (embed; bug #555332)
1317            - zope2.10 <unfixed> (embed; bug #555333)
1318            - zope2.11 <removed> (embed; bug #555334)
1319            - python-mechanize <unknown> (embed)
1320            - twill <unknown> (embed)
1321    
1322    python-mechanize
1323            - zope2.10 <unfixed> (embed; bug #555337)
1324            - zope2.11 <removed> (embed; bug #555338)
1325            - twill <unknown> (embed; bug #555339)
1326    
1327    pexpect
1328            - duplicity 0.6.06-1 (embed; bug #555361)
1329            - hplip <unfixed> (embed; bug #555362)
1330            - smart <unfixed> (embed; bug #555363)
1331    
1332    pyparsing
1333            - bauble <unfixed> (embed; bug #555366)
1334            - boa-constructor 0.6.1-8 (embed; bug #555367)
1335            - calibre <unfixed> (embed; bug #555368)
1336            - matplotlib <unfixed> (embed; bug #531024)
1337            - zhpy 1.7.3.1-1 (embed; bug #555370)
1338            - polybori <unknown> (embed)
1339            - python-whoosh <unknown> (embed)
1340            - twill <unknown> (embed)
1341            - zope-textindexng3 <unknown> (embed)
1342    
1343    python-pysqlite2
1344            - python2.4 <unfixed> (embed; bug #553403)
1345            - python2.5 <unfixed> (embed; bug #553403)
1346    
1347    celementtree
1348            - python2.5 <unfixed> (embed)
1349            - smart <unfixed> (embed)
1350    
1351    elementtree
1352            - python2.5 <unfixed> (embed)
1353            - python2.6 <unfixed> (embed)
1354            - bzr 2.1.0~rc2-1 (embed; bug #555343)
1355            - gedit 2.28.2-1 (embed; bug #555344)
1356            - smart <unfixed> (embed)
1357            - solfege <unfixed> (embed; bug #555345)
1358            - w3af <unfixed> (embed; bug #555346)
1359            - python-qt4 <unknown> (embed)
1360            - sphinx <unknown> (embed)
1361            - python-nltk <itp> (embed)
1362    
1363    python2.5
1364            - python2.4 <unfixed> (old-version)
1365            - jython <unfixed> (embed)
1366            NOTE: embeds many stdlib modules
1367            - python-django <unfixed> (embed; bug #555419)
1368            NOTE: embeds stdlib modules: doctest, decimal
1369            - gamera 3.2.3-1 (embed)
1370            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1371            - boa-constructor <unfixed> (embed; bug #555426)
1372            NOTE: embeds stdlib modules: ConfigParser, tarfile, zipfile, xmlrpclib
1373            - nicotine <unfixed> (embed; bug #555427)
1374            NOTE: embeds stdlib modules: ConfigParser
1375            - museek+ <unfixed> (embed; bug #555428)
1376            NOTE: embeds stdlib modules: ConfigParser
1377            - vegastrike-data <removed> (embed)
1378            NOTE: embeds many stdlib modules
1379            - codespeak-lib 1.1.1-1 (embed; bug #555420)
1380            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1381            - config-manager <unfixed> (embed; bug #555423)
1382            NOTE: embeds stdlib modules: optparse
1383            - jhbuild 2.28.0-1 (embed; bug #555421)
1384            NOTE: embeds stdlib modules: optparse, subprocess
1385            - smart <unfixed> (embed; bug #555432)
1386            NOTE: embeds stdlib modules: optparse
1387            - pyprotocols 1.0a.svn20070625-5 (embed; bug #555433)
1388            NOTE: embeds stdlib modules: doctest
1389            - ruledispatch 0.5a.svn20080510-4 (embed; bug #555434)
1390            NOTE: embeds stdlib modules: doctest
1391            - distribute <unfixed> (embed)
1392            NOTE: embeds stdlib modules: doctest
1393            - python-setuptools <unfixed> (embed; bug #555435)
1394            NOTE: embeds stdlib modules: doctest
1395            - zope.testing <unfixed> (embed; bug #555436)
1396            NOTE: embeds stdlib modules: doctest
1397            - translate-toolkit <unfixed> (embed; bug #555422)
1398            NOTE: embeds stdlib modules: textwrap, contextlib
1399            - libtpclient-py <unfixed> (embed; bug #555424)
1400            NOTE: embeds stdlib modules: subprocess
1401            - grass <unfixed> (embed; bug #555425)
1402            NOTE: embeds stdlib modules: subprocess
1403            - coherence <unfixed> (embed; bug #555429)
1404            NOTE: embeds stdlib modules: uuid
1405            - python-django-extensions 0.4.2pre+git200911182050-1 (embed; bug #555430)
1406            NOTE: embeds stdlib modules: uuid
1407            - setroubleshoot <removed> (embed; bug #555431)
1408            NOTE: embeds stdlib modules: uuid
1409            - linkchecker <unfixed> (embed; bug #555414)
1410            NOTE: embeds msgfmt.py script
1411            - imdbpy <unfixed> (embed)
1412            NOTE: embeds msgfmt.py script
1413            - kiwi <unfixed> (embed)
1414            NOTE: embeds msgfmt.py script
1415            - moin <unfixed> (embed)
1416            NOTE: embeds msgfmt.py script, stdlib modules: cgitb, difflib, tarfile
1417            - plone3 <removed> (embed)
1418            NOTE: embeds msgfmt.py script
1419            - roundup <unfixed> (embed)
1420            NOTE: embeds msgfmt.py script, stdlib modules: cgitb
1421            - rednotebook <unfixed> (embed; bug #555415)
1422            NOTE: embeds msgfmt.py script
1423            - turbogears <unfixed> (embed)
1424            NOTE: embeds msgfmt.py script
1425            - elisa <unfixed> (embed)
1426            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1427            - calibre <unfixed> (embed)
1428            NOTE: embeds msgfmt.py script, stdlib modules: zipfile
1429            - mailman 1:2.1.13-1 (embed; #555416)
1430            NOTE: embeds msgfmt.py script
1431            - python-docutils <unknown> (embed)
1432            NOTE: embeds stdlib modules: optparse, textwrap
1433            - python-imaging <unknown> (embed)
1434            NOTE: embeds stdlib modules: doctest
1435            - python-mechanize <unknown> (embed)
1436            NOTE: embeds stdlib modules: doctest
1437            - twill <unknown> (embed)
1438            NOTE: embeds stdlib modules: subprocess
1439            - zeroc-ice <unknown> (embed)
1440            NOTE: embeds stdlib modules: subprocess
1441            - wxwidgets2.8 <unknown> (embed)
1442            NOTE: embeds stdlib modules: subprocess
1443            - cycle <unknown> (embed)
1444            NOTE: embeds msgfmt.py script
1445            - deluge <unknown> (embed)
1446            NOTE: embeds msgfmt.py script
1447            - opendict <unknown> (embed)
1448            NOTE: embeds msgfmt.py script
1449            - openerp-client <unknown> (embed)
1450            NOTE: embeds msgfmt.py script
1451            - rapidsvn <unknown> (embed)
1452            NOTE: embeds msgfmt.py script
1453            - wammu <unknown> (embed)
1454            NOTE: embeds msgfmt.py script
1455            - gaphor <unknown> (embed)
1456            NOTE: embeds msgfmt.py script
1457            - pida <unknown> (embed)
1458            NOTE: embeds msgfmt.py script
1459            - python-formencode <unknown> (embed)
1460            NOTE: embeds msgfmt.py script
1461            - duplicity <unfixed> (embed)
1462            NOTE: embeds stdlib module: urlparse, tarfile
1463            - pygopherd <unfixed> (embed)
1464            NOTE: embeds stdlib module: zipfile
1465    
1466    argparse
1467            - twill <unfixed> (embed; bug #555347)
1468            - ipython <unfixed> (embed; bug #555348)
1469    
1470    coherence
1471            - elisa <unfixed> (embed; bug #555335)
1472    
1473    simpletal
1474            - plastex <unfixed> (embed; bug #555371)
1475    
1476    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1477            - postr <unfixed> (embed)
1478            - elisa <unfixed> (embed)
1479    
1480    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1481            - apertium-tolk <unfixed> (embed)
1482            - ipython <unfixed> (embed)
1483            - virtaal <unfixed> (embed)
1484    
1485    distribute
1486            - setuptools <removed> (old-version)
1487    
1488    rails
1489            - jruby1.2 <removed> (embed) [./bench/rails/*]
1490            NOTE: jruby is in non-free, it probably includes rails too
1491            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1492            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1493            - thin <unfixed> (embed) [./spec/rails_app/*]
1494            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1495            NOTE: be dangerous if developers are naively basing their code off of the examples
1496            NOTE: prototype.js is among the example files
1497    
1498    lucene2 (prototype.js is among the embeds in the following)
1499            - lucene <unfixed> (old-version)
1500            - pylucene <unfixed> (embed)
1501            - libpdfbox-java <unfixed> (embed)
1502            - libfontbox-java <unfixed> (embed)
1503            - libjempbox-java <unfixed> (embed)
1504            - solr <unfixed> (embed)
1505    
1506    unicode-data
1507            - syslinux <unfixed> (embed)
1508            - camomile <unfixed> (embed)
1509            - fribidi <unfixed> (embed)
1510            - m17n-db <unfixed> (embed)
1511            - sbcl <unfixed> (embed)
1512            - heimdal <unfixed> (embed)
1513            - icu <unfixed> (embed)
1514            - icu4j <unfixed> (embed)
1515            - krb5 <unfixed> (embed)
1516            - moodle <unfixed> (embed)
1517            - openldap <unfixed> (embed)
1518            - pike7.6 <unfixed> (embed)
1519            - samba <unfixed> (embed)
1520            - samba4 <unfixed> (embed)
1521            - cmucl <unfixed> (embed)
1522            - typo3-src <unfixed> (embed)
1523            - mauve <unfixed> (embed)
1524            - texlive-bin <unfixed> (embed)
1525            - ypsilon <unfixed> (embed)
1526            - jeuclid <unfixed> (embed)
1527            - charmap.app <unfixed> (embed)
1528            - clisp <unfixed> (embed)
1529            - gnulib <unfixed> (embed)
1530            - opensrs-client <unfixed> (embed)
1531            - saxonb <unfixed> (embed)
1532            - rails <unfixed> (embed)
1533    
1534    feedparser
1535            - rawdog <unfixed> (embed; bug #383422)
1536            - miro <unfixed> (embed; bug #555351)
1537            - calibre <unfixed> (embed; bug #555352)
1538            - freevo <unfixed> (embed; bug #555353)
1539            - pida <unfixed> (embed; bug #555354)
1540            - planet-venus <unfixed> (embed; bug #555355)
1541            - plone3 <removed> (embed; bug #555356)
1542            - exaile 0.2.14+debian-1 (embed)
1543            - screenlets 0.1.2-3 (embed)
1544            NOTE: included twice
1545    
1546    agg:
1547            - matplotlib <unfixed> (embed: bug #377271)
1548            - contextfree <unfixed> (embed)
1549            NOTE: since 2.2-1 it links statically to system libagg, but still uses the embedded copy
1550            - exactimage <unfixed> (embed)
1551            - python-enable <unfixed> (embed)
1552            - mapnik 0.5.1-3 (embed)
1553            NOTE: links statically to agg, but shared library is not available (bug #377271)
1554    
1555    vtk
1556            - paraview <unfixable> (embed; bug #495426)
1557    
1558    txt2tags
1559            - rednotebook <unfixed> (embed)
1560    
1561    htmltextview (not packaged in Debian, http://www.gnome.org/~gjc/htmltextview.py)
1562            - gajim <unfixed> (embed)
1563            - emesene <unfixed> (embed)
1564            - convirt <unfixed> (embed)
1565            - pida <unfixed> (embed)
1566            - rednotebook <unfixed> (embed)
1567    
1568    horde3 (prototype.js is among the embeds in the following)
1569            - mnemo2 <unfixed> (embed)
1570            - nag2 <unfixed> (embed)
1571            - wordpress <unfixed> (embed)
1572            NOTE: Text_Diff (wp-includes/Text/Diff*)
1573    
1574    cimg
1575            - gmic <unfixed> (embed)
1576    
1577    mootools
1578            - kdenetwork <unfixed> (embed)
1579            - gallery <unfixed> (embed)
1580            - jspwiki <unfixed> (embed)
1581            - vdr-plugin-live <unfixed> (embed)
1582            - perl-doc-html <unfixed> (embed)
1583    
1584    openldap
1585            - openldap2.3 <removed> (old-version)
1586    
1587    grub2
1588            - grub <unfixed> (old-version)
1589    
1590    gnupginterface
1591            - duplicity <unfixed> (embed)
1592    
1593    python-dateutil
1594            - awn-extras-applets <unfixed> (embed)
1595            - matplotlib <unknown> (embed)
1596    
1597    cups
1598            - cupsys <removed> (old-version)
1599    
1600    yui
1601            - bcfg2 <not-affected> (present in source but not included in any binary files)
1602            - serendipity 1.5.3-1 (embed; bug #557746)
1603            - moodle 1.8.2.dfsg-5 (embed)
1604            - jifty 0.91117-1 (embed; bug #557748)
1605            - webgui 7.7.26-1 (embed)
1606            - loggerhead 1.17-1 (embed)
1607            - otrs2 2.4.7+dfsg1-1 (embed; bug #592146)
1608    
1609    quake3 (vanilla source not packaged in debian)
1610            - openarena <unfixable> (fork)
1611    
1612    quake2 (vanilla source not packaged in debian)
1613            - alien-arena <unfixable> (fork)
1614            - warsow <unfixable> (fork)
1615    
1616    libtheora
1617            - iceweasel <not-affected> (uses xulrunner)
1618            - xulrunner <unfixed> (embed; bug #540959)
1619            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
1620            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
1621            - iceape <unfixed> (embed; bug #559276)
1622            [etch] - iceape <not-affected> (introduced in iceape 2.0)
1623            [lenny] - iceape <not-affected> (introduced in iceape 2.0)
1624    
1625    dtoa
1626            - bfilter <unfixed> (embed)
1627            - cacao <removed> (embed)
1628            - cdrdao <unfixed> (embed)
1629            - classpath <unfixed> (embed)
1630            - freej <unfixed> (embed)
1631            - iceape <unfixed> (embed)
1632            - iceweasel <unfixed> (embed)
1633            - jscoverage <unfixed> (embed)
1634            - kde4libs <unfixed> (embed)
1635            - kdelibs <unfixed> (embed)
1636            - kompozer <unfixed> (embed)
1637            - libv8 <unfixed> (embed)
1638            - mono <unfixed> (embed)
1639            - newlib <unfixed> (embed)
1640            - nspr <unfixed> (embed)
1641            - php5 <unfixed> (embed)
1642            - polyml <unfixed> (embed)
1643            - qt4-x11 <unfixed> (embed)
1644            - rhino <unfixed> (embed)
1645            NOTE: code translated to Java
1646            - ruby1.8 <unfixed> (embed)
1647            - ruby1.9 <unfixed> (embed)
1648            - ruby1.9.1 <unfixed> (embed)
1649            - sdd <unfixed> (embed)
1650            - sfind <unfixed> (embed)
1651            - star <unfixed> (embed)
1652            - tinymux <unfixed> (embed)
1653            - virtualbox-ose <unfixed> (embed)
1654            - webkit <unfixed> (embed)
1655            - xulrunner <unfixed> (embed)
1656    
1657    ipc (not packaged in Debian; see http://mozdev.org/pipermail/enigmail/2009-November/011678.html)
1658            - firegpg <unfixed> (embed)
1659            - enigmail <unfixed> (embed)
1660    
1661    ptmalloc (not packaged in Debian)
1662            - crystalspace <unfixed> (embed)
1663            - qt4-x11 <unfixed> (embed)
1664    
1665    svgalib
1666            - usplash <unfixed> (embed)
1667    
1668    bogl
1669            - usplash <unfixed> (embed)
1670    
1671    taglist
1672            - usplash <unfixed> (embed)
1673    
1674    portaudio
1675            - audacity <unfixed> (embed; bug #323711)
1676    
1677    nyquist
1678            - audacity <unfixed> (embed)
1679            NOTE: embeds a forked nyquist with support for a shared library
1680    
1681  halibut:  vamp-plugin-sdk
1682  nsis          - audacity <unfixed> (embed)
1683    
1684  libghttp:  wordpress
1685  hotway          - libwordpress-xmlrpc-perl <removed> (embed) [./xmlrpc.php]
1686            - wordpress-mu <removed> (fork)
1687    
1688  etl-dev (will be renamed to libetl-dev soon):  php5
1689  synfig          - php4 <removed> (old-version)
1690    
1691  libmms:  classpath
1692  xine-lib          - libgnucrypto-java <removed> (embed; bug #559788)
 mimms  
1693    
1694  FCKeditor:  libtool
1695  knowledgeroot          - apr <unfixed> (static; bug #489625)
1696            NOTE: ships copy of libtool in libapr1-dev; was 'embed' before 1.3.2-3
1697  TinyMCE:          - arts <unfixed> (embed)
1698  wordpress          - bochs 2.4.2-1 (embed; bug #560884)
1699  moodle          - camserv <unfixed> (embed)
1700  knowledgeroot          - collectd 4.8.2-1 (embed)
1701  joomla (ITP)          - courier-authlib 0.58-4 (embed)
1702            NOTE: The etch version of courier-authlib was the earliest version checked, might be fixed earlier
1703  scintilla:          - cvsnt 2.5.04.3236-1.2 (embed)
1704  scite          - dico <not-affected> (Uses the system copy of ltdl)
1705  qscintilla          - freeradius 0.1+20010527-1 (embed)
1706  geany          NOTE: Earliest reference I could find from the changelog is from 27 May 2001
1707            - ggobi 2.1.9~20091212-1 (embed)
1708  libphp-adodb:          - glame 2.0.1-4 (embed)
1709  gallery2          NOTE: The etch version of glame was the earliest version checked, might be fixed earlier
1710  phppgadmin          - gnash 0.8.7-2 (embed)
1711  egroupware          - gnu-smalltalk <unfixed> (embed; bug #566777)
1712  phpwiki          - google-gadgets 0.10.5-0.3 (embed)
1713  moodle          NOTE: 0.10.5-0.3 was the earliest version checked, was fixed earlier
1714  cacti (dependency exists, but internal version is used -- only in sarge, fixed in etch)          - graphicsmagick 1.3.5-6 (embed)
1715            - graphviz 2.8-3 (embed)
1716  gzip:          NOTE: The etch version of graphviz was the earliest version checked, might be fixed earlier
1717  linux-kernel (lib/inflate.c)          - guile-1.6 1.6.8-7 (embed)
1718  klibc (based on linux-kernel gzip code)          - hamlib 1.2.11-1 (embed)
1719  busybox          - hercules 3.06-1.2 (embed)
1720            - jags 1.0.4-3 (embed; bug #560864)
1721            - kdelibs <unfixed> (embed)
1722            - libannodex <removed> (embed)
1723            - libextractor 0.5.23+dfsg-4 (embed)
1724            - libmcrypt <not-affected> (libtool source present but not included in any of the binary packages)
1725            - libtunepimp 0.5.3-7.3 (embed)
1726            - mp4h 1.3.1-4.1 (embed)
1727            - naim <removed> (embed)
1728            - parser-mysql <unfixed> (embed)
1729            - pinball 0.3.1-11 (embed)
1730            - redland <unfixed> (embed)
1731            - siproxd <unfixed> (embed)
1732            - ski <unfixed> (embed)
1733            - synfig 0.62.00-1 (embed)
1734            - unixodbc 2.2.4-5 (embed)
1735            - xmlsec1 <not-affected> (Doesn't enable dynamic loading of crypto modules)
1736            - clamav 0.95+dfsg-1 (embed)
1737            - imagemagick 6:6.2.3.1-1 (embed)
1738            - hypre 2.4.0b-5 (embed)
1739            - lam <unfixed> (embed)
1740            - openmpi <unfixable> (embed; bug #559386)
1741            - parser <unfixed> (embed)
1742            - pdsh 2.18-5 (embed; bug #560892)
1743            - sbnc 1.2-8 (embed)
1744            - sdcc <unfixed> (embed)
1745            - wml <not-affected> (The embedded ltdl isn't used, instead mp4h is used, see 559841)
1746            - proftpd-dfsg <unfixed> (embed; bug #561748)
1747            - babel 1.4.0.dfsg-5 (embed)
1748            - libprelude 0.9.14-2 (embed)
1749            - heartbeat 2.1.4-7 (embed)
1750            NOTE: From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
1751            NOTE: might've been fixed earlier
1752            - gcc-* <unknown> (embed)
1753    
1754    ocamlgsl
1755            - orpie 1.5.1-7.1 (embed; bug #550058)
1756    
1757    xdotool
1758            - keynav <unfixed> (embed; bug #560103)
1759    
1760    bulletphysics (not packaged; http://www.bulletphysics.org/)
1761            - supertuxkart <unfixed> (embed)
1762            - blender <unfixed> (embed)
1763    
1764    ghostscript
1765            - gs-gpl <removed> (old-version)
1766    
1767    icedove
1768            - thunderbird <removed> (old-version)
1769    
1770    sizzlejs (not packaged in Debian, http://sizzlejs.com/)
1771            - jquery <unfixed> (embed)
1772    
1773    sed
1774            - ssed <unfixed> (fork)
1775    
1776    phpatomlib (http://code.google.com/p/phpatomlib)
1777            - wordpress <unfixed> (embed)
1778    
1779    Services_JSON (http://pear.php.net/package/Services_JSON)
1780            - wordpress <unfixed> (embed)
1781    
1782    phpass (http://www.openwall.com/phpass/)
1783            - gallery2 <unfixed> (embed)
1784            - wordpress <unfixed> (embed)
1785            - typo3-src <unfixed> (modified-embed)
1786            NOTE: file refers to drupal, maybe there's a copy somewhere there
1787            NOTE: a copyright owner search didn't match anything
1788            - libauthen-passphrase-perl <unfixable> (fork)
1789            NOTE: perl implementation of phpass
1790    
1791    squirrelmail
1792            - wordpress <unfixed> (embed)
1793            NOTE: class-pop3.php
1794    
1795    ezSQL (http://www.woyano.com/jv/ezsql)
1796            - wordpress <unfixable> (fork)
1797            NOTE: wp-db.php
1798    
1799    Diff.php (Clay Loveless' version/killersoft.com)
1800            - php-versioncontrol-svn <unfixed>
1801    
1802    libm (provided by libc)
1803            - spring <unfixed> (embed)
1804            NOTE: embedded by embedded copy of streflop
1805            - aide <unfixed> (static)
1806            - busybox <unfixed> (static)
1807            - mindi-busybox <unfixed> (static)
1808            - qemu <unfixed> (static)
1809            NOTE: qemu-user-static
1810            - tuxonice-userui <unfixed> (static)
1811            - zsh <unfixed> (static)
1812            NOTE: zsh-static
1813            - tripwire <unfixed>
1814    
1815    streflop
1816            - spring <unfixed> (embed)
1817    
1818    minizip
1819            - spring <unfixed> (embed)
1820    
1821    oscpack
1822            - spring <unfixed> (embed)
1823    
1824    hpiutil2
1825            - spring <unfixed> (embed)
1826    
1827    p7zip
1828            - spring <unfixed> (embed)
1829    
1830    pythonqt (doesn't seem to be python-qtN, unknown source)
1831            - fontmatrix <unfixed> (embed)
1832            - elmerfem <unfixed> (embed)
1833    
1834    iepngfix (not packaged in Debian; http://www.twinhelix.com/css/iepngfix/)
1835            - docvert <unfixed> (embed)
1836            - jifty <unfixed> (embed)
1837            - kdenetwork <unfixed> (embed)
1838            - mediatomb <unfixed> (embed)
1839            - plastex <unfixed> (embed)
1840            - plone3 <removed> (embed)
1841            - python-chaco <unfixed> (embed)
1842            - python-docutils <unfixed> (embed)
1843            - s5 <unfixed> (embed)
1844            - zope2.10 <unfixed> (embed)
1845            - zope2.11 <removed> (embed)
1846            - cython <not-affcted> (embed)
1847            NOTE: part of documentation, which is not installed into the binary package
1848    
1849    python-docutils
1850            - zope2.10 <unfixed> (embed)
1851            - zope2.11 <removed> (embed)
1852    
1853    tesseract
1854            - ocropus <unfixed> (static)
1855    
1856    antlr
1857            - kdevelop <unfixed> (embed)
1858    
1859    libxerces2
1860            - openjdk-6 <unfixed> (embed)
1861    
1862    kfreebsd-8
1863            - kfreebsd-7 <unfixed> (old-version)
1864            - kfreebsd-6 <removed> (old-version)
1865    
1866    ruby1.9.1
1867            - ruby1.9 <unfixed> (old-version)
1868            - ruby1.8 <unfixed> (old-version)
1869    
1870    maildrop
1871            - courier <unfixed> (embed) [./maildrop]
1872    
1873    glee
1874            - warzone2100 <not-affected> (embed)
1875    
1876    phing
1877            - symfony <unfixed> (embed)
1878    
1879    pake
1880            - symfony <unfixed> (embed)
1881    
1882    propel
1883            - symfony <unfixed> (embed)
1884    
1885    creole
1886            - symfony <unfixed> (embed)
1887    
1888    hfsutils
1889            - cdrkit <unfixed> (embed; bug #570187)
1890            NOTE: embeds hfsutils code in genisoimage
1891    
1892    cdrkit
1893            - grub2 <unfixed> (embed; bug #570156)
1894            NOTE: genisoimage imported into grub-mkisofs
1895    
1896    kdebase-workspace
1897            - kdebase <unfixed> (old-version)
1898    
1899    file
1900            - php5 <unfixable> (modified-embed)
1901            [lenny] - php5 <not-affected>
1902    
1903    cdb
1904            - php5 <unfixed> (embed)
1905    
1906    libmbfl (itp: #570708)
1907            - php5 <unfixed> (embed)
1908            NOTE: PHP is actually the current upstream, ITP is of that code
1909    
1910    libonig
1911            - php5 5.3.2-1 (embed)
1912    
1913    xmlrpc-epi
1914            - php5 <unfixed> (embed)
1915    
1916    swt-gtk
1917            - eclipse <unfixed> (embed; bug #538808)
1918    
1919    txt2html
1920            - wml 2.0.11ds2-1 (embed)
1921    
1922    ca-certificates
1923            - nss <not-affected> (certificates are in source, but not included in any of the binary packages)
1924    
1925    openexr
1926            - freeimage <unfixed> (embed)
1927    
1928    libmng
1929            - freeimage <unfixed> (embed)
1930    
1931    openjpeg
1932            - freeimage <unfixed> (embed)
1933    
1934    libjpeg6b
1935            - freeimage <unfixed> (embed)
1936    
1937    libjpeg (don't know what exact version)
1938            - dcmtk <unfixed>
1939            - gdcm <unfixed>
1940            - insighttoolkit <unfixed>
1941            - openarena 0.8.5-5+exp1 (bug #495966)
1942            - outguess <unfixed>
1943            - squeak-vm <unfixed> (embed)
1944            - tremulous <unfixed>
1945            - tuxonice-userui <unfixed> (static)
1946            - fpc <unfixed> (static)
1947            - lazarus <unfixed> (static)
1948            NOTE: inherited from fpc, see #472304
1949            - mseide-msegui <unfixed> (static)
1950            NOTE: inherited from fpc, see #472304
1951            - easymp3gain <unfixed> (static)
1952            NOTE: inherited from fpc, see #472304
1953            - winff <unfixed> (static)
1954            NOTE: inherited from fpc, see #472304
1955            - texlive-bin <not-affected> (included in upstream source as dependency of libgd2, but not built or included in any of the binary packages)
1956    
1957    
1958    lxr
1959            - lxr-cvs <unfixed> (embed)
1960    
1961    libfile-copy-recursive-perl
1962            - r-base <unfixed> (embed; bug #577427)
1963            - r-base-core-ra <unfixed> (embed; bug #577429)
1964    
1965    delimmatch
1966            - r-base <unfixed> (embed; bug #577433)
1967            - r-base-core-ra <unfixed> (embed; bug #577434)
1968    
1969    libsmf (ITP: #572558)
1970            - denemo <unfixed> (embed)
1971            NOTE: http://lists.debian.org/debian-mentors/2010/04/msg00269.html
1972    
1973    libselinux
1974            - dpkg 1.15.6 (static)
1975    
1976    xinha (ITP: #479708)
1977            - horde3 <unfixed>
1978            - serendipity <unfixed>
1979            - openacs <unfixed>
1980            - dotlrn <unfixed>
1981    
1982    dvipng
1983            - texlive-bin <not-affected> (code present in source but not included in the binary packages)
1984    
1985    dvipdfmx
1986            - texlive-bin <unfixed> (embed)
1987            NOTE: this is intentionally part of the package now, and the separate dvipdfmx package has been removed from sid/squeeze
1988    
1989    lcdf-typetools
1990            - texlive-bin 2009-1 (embed)
1991    
1992    tex4ht
1993            - texlive-bin 2009-1 (embed)
1994    
1995    freetype
1996            - texlive-bin 2009-1 (embed)
1997    
1998    freetype2
1999            - texlive-bin 2009-1 (embed)
2000    
2001    silgraphite
2002            - texlive-bin <unfixed> (embed)
2003    
2004    unzip
2005            - texlive-bin 2009-1 (embed)
2006    
2007    jbig2dec
2008            - ghostscript 8.71~dfsg2-1 (embed)
2009    
2010    libxml2
2011            - chromium-browser 5.0.375.29~r46008-1
2012    
2013    protobuf
2014            - chromium-browser 5.0.375.70~r48679-2
2015    
2016    libv8
2017            - chromium-browser 5.0.375.38~r46659-1
2018    
2019    nspr
2020            - chromium-browser 5.0.375.29~r46008-3
2021    
2022    yasm
2023            - chromium-browser 5.0.375.29~r46008-2
2024    
2025    libxslt
2026            - chromium-browser 5.0.375.29~r46008-1
2027    
2028    miniupnpc (not packaged in Debian; ITP bug #444392)
2029            - warzone2100 <unfixed> (embed)
2030    
2031    iniparser (not packaged in Debian; RFP bug #582657)
2032            - warzone2100 <unfixed> (modified-embed)
2033    
2034    pyglet
2035            - sympy <unfixed> (embed; bug #459716)
2036    
2037    mpmath
2038            - sympy <unfixed> (embed; bug #541746)
2039    
2040    curl
2041            - cmake 2.6.0-6 (embed)
2042            NOTE: Might be fixed earlier. Lenny version recorded.
2043            - criticalmass <unfixed> (static; bug #599061)
2044            - wengophone 2.1.0~beta1-svn9983-1 (embed)
2045    
2046    lib3ds
2047            - boson <unfixed> (embed; bug #600900)
2048            - openscenegraph <unfixed> (embed; bug #601181)
2049    
2050    xcftools
2051            - gnome-xcf-thumbnailer <unfixed> (embed)

Legend:
Removed from v.4835  
changed lines
  Added in v.15569

  ViewVC Help
Powered by ViewVC 1.1.5