/[secure-testing]/data/embedded-code-copies
ViewVC logotype

Diff of /data/embedded-code-copies

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

revision 7923 by stef-guest, Mon Jan 14 21:43:39 2008 UTC revision 13215 by jwilk-guest, Thu Nov 5 17:40:19 2009 UTC
# Line 1  Line 1 
1  Embedded code copies  Embedded code copies
2  ====================  ====================
3    
4  This file collects cases, where a source package embeds code from  This file collects source packages that embed code from other projects.
5  other projects which is considered bad for fixing security flaws  This is considered bad for fixing security flaws because the fix needs
6  because the fix needs to be applied in multiple source packages.  to be applied in multiple source packages.
7    
8  Format:  Format:
9  <srcpkg> (<optional comment about srcpkg>)  <srcpkg> (<optional comment about srcpkg>)
10          - <embedding srcpkg> <status> (<sort>; bug #<number>)          - <embedding srcpkg> <status> (<sort>; bug #<number>)
11          NOTE: optional comments about the linkage of the embedding srcpkg          NOTE: optional comments about the linkage of the embedding srcpkg
12    
13  status: version number fixing the embedded copy, <unfixed>, <removed>, <itp> or <unknown> if the version number can not be determined  status: version number fixing the embedded copy, <unfixed>, <removed>,
14            <itp>, <not-affected>, <unknown> if the version number can not
15            be determined, or <unfixable> for unavoidable cases (e.g., forks
16            that add real value)
17  sort: static (linking statically against a lib)  sort: static (linking statically against a lib)
18        embed (embedding a copy of the library into another source package)        embed (embedding a copy of the library into another source package)
19        fork (the package is not just embedding code but it is a fork and thus might share parts of the source code)        fork (the package is not just embedding code but it is a fork and
20                thus might share parts of the source code)
21          old-version (the package is an older version of essentially
22                       the same code)
23    
24  The srcpkg might be some string to identify the code if there is no specific source package.  The srcpkg might be some string to identify the code if there is no
25    specific source package.
26    
27  Everything up to the next line is ignored  Everything up to the next line is ignored.
28  ---BEGIN  ---BEGIN
29  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)  xpdf (some srcpkgs use xpdf2 code, some xpdf3 code)
30          NOTE: Fixed packages link to poppler library unless otherwise noted          NOTE: Fixed packages link to poppler library unless otherwise noted
         - gpdf <removed>  
         [sarge] - gpdf <unfixed>  
         NOTE: has been replaced by evince in etch  
31          - pdftohtml <unknown>          - pdftohtml <unknown>
32          [sarge] - pdftohtml <unfixed>          [sarge] - pdftohtml <unfixed>
33          [etch] - pdftohtml <unfixed>          [etch] - pdftohtml <unfixed>
34          NOTE: has been replaced by poppler-utils          NOTE: has been replaced by poppler-utils
35          - kdegraphics <unfixed> (embed; bug #436164)          - kdegraphics 4:4.2.2-1 (embed; bug #436164)
36          NOTE: the kpdf replacement in KDE 4 is using poppler          - texlive-base 3.0-12 (embed)
         - tetex-bin 3.0-12 (embed)  
37          - texlive-bin 2007-1 (embed)          - texlive-bin 2007-1 (embed)
38          NOTE: links to poppler          NOTE: links to poppler
39          - koffice <unfixed> (embed; bug #436163)          - koffice <unfixed> (embed; bug #436163)
40          - libextractor 0.5.12-1 (embed)          - libextractor 0.5.12-1 (embed)
41          NOTE: libextractor is using its own pdf decoder now          NOTE: libextractor is using its own pdf decoder now
         - libextractor 0.5.12-1 (embed)  
         - pdfkit.framework 0.8-4 (embed)  
42          - ipe <unfixed> (embed)          - ipe <unfixed> (embed)
43          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp          NOTE: embeds small parts with renamed source files: ipestdfonts.cpp, ipefonts.cpp, ipedct.cpp
44          - ruby-gnome2 <unknown> (embed)          - ruby-gnome2 <unknown> (embed)
45          NOTE: copy only present in source but links to poppler          NOTE: copy only present in source but links to poppler
46            - pdfedit <unfixed> (embed; bug #510794)
47            - swftools <unfixed> (embed; bug #551293)
48            - poppler <unfixable> (fork)
49    
50  ppmd  ppmd
51          - libcomplearn-mod-ppmd <unfixed> (embed; bug #458152)          - libcomplearn-mod-ppmd <unfixed> (fork)
52            NOTE: discussion in #458152
53    
54    libevent
55            - transmission 1.71-1 (embed; bug #529372)
56    
57    lrmi
58            - read-edid 2.0.0-1 (embed; bug #495131)
59    
60    peercast
61            - gnome-peercast <removed> (embed)
62            [etch] - gnome-peercast <unfixed> (embed)
63    
64  silc-toolkit  silc-toolkit
65          - silc-client 1.1~beta6-1 (embed)          - silc-client 1.1~beta6-1 (embed)
66    
67    icclib
68            - ghostscript <unfixed> (embed)
69            - argyll <unfixed> (embed)
70    
71  dietlibc  dietlibc
72          - ccontrol 0.9.1+20071204-1 (static)          - ccontrol 0.9.1+20071204-1 (static)
73    
74    libmikmod
75            - sdl-mixer1.2 <unfixed> (embed)
76            TODO: report bug
77    
78  libiax  libiax
79          - iaxmodem <unfixed> (embed)          - iaxmodem <unfixable> (embed; bug #548885)
80    
81    spandsp
82            - iaxmodem <unfixable> (embed; bug #548885)
83    
84  zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)  zlib (lots of apps embed a copy, but link dynamically, but there are a few exceptions)
85          - dpkg <unfixed> (embed)          - dpkg <unfixed> (embed)
# Line 67  zlib (lots of apps embed a copy, but lin Line 93  zlib (lots of apps embed a copy, but lin
93          - mrtg 2.12.2-1 (embed)          - mrtg 2.12.2-1 (embed)
94          - rpm <unknown> (embed)          - rpm <unknown> (embed)
95          NOTE: pinged anibal since when rpm was fixed          NOTE: pinged anibal since when rpm was fixed
96            - tuxcmd-modules <unfixed> (embed)
97            - zsync <unfixed>
98            - tra <unfixed>
99            - sash <unfixed>
100            - nsis <unfixed>
101            - mseide-msegui <unfixed>
102            NOTE: mseide
103            - mirrordir <unfixed>
104            - poco <unfixed>
105            - klibc <unfixed>
106            - ghostscript <unfixed>
107            - freeimage <unfixed>
108            - clamav <unfixed> (fork)
109            NOTE: from the changelog: "libclamav6 does indeed duplicate parts of the zlib code, but there is not way around that"
110            - tuxonice-userui <unfixed>
111            - plt-scheme <unfixed>
112            - perl <unfixed>
113            - paraview <unfixed>
114            - gcvs <unfixed>
115            - dump <unfixed>
116            - aide <unfixed> (static)
117            - dar <unfixed> (static)
118            - avfs <unfixed>
119            - fpc <unfixed>
120            - winff <unfixed>
121            NOTE: inherited from fpc, see #472304
122            - lazarus <unfixed>
123            NOTE: inherited from fpc, see #472304
124            - erlang <unfixed> (embed)
125            - gamera 3.2.3-1 (embed)
126            - python2.4 <unfixed> (embed; bug #553403)
127            - python2.5 <unfixed> (embed; bug #553403)
128    
129    dulwich
130            - hg-git 0.1.0-1 (embed; bug #541996)
131    
132    libvigraimpex
133            - hugin <unfixed> (embed; bug #542259)
134            - enblend-enfuse <unfixed> (embed; bug #542258)
135            - gamera 3.2.3-1 (embed)
136    
137  libbz2  libbz2
138          - dpkg <unfixed> (static)          - dpkg <unfixed> (static)
139    
140  ekg  libgadu
141          - centericq <unfixed> (embed)          - centericq <unfixed> (embed)
142          - gaim <unfixed> (embed)          - pidgin <not-affected> (embed)
143          - pigdin <unfixed> (embed)(links dynamically against libgadu)          [etch] - gaim 1:2.0.0+beta3-3 (embed; bug #360280)
144          - kopete 4:3.3.2-5 (embed)          - kdenetwork 4:3.3.2-5 (embed)
145          - kadu <unfixed> (embed)          NOTE: from kdenetwork: kopete
146          - gadu <unfixed> (embed)          - ekg 1:1.8~rc0-1 (embed)
147          NOTE: g/kadu not packaged in Debian yet          - kadu 0.6.0.2-3 (embed; bug #504430)
148            - gadu <itp> (embed)
149    
150  xmlrpc (which package is the "origin" of this code?)  xmlrpc (which package is the "origin" of this code?)
151          - drupal <unfixed> (embed)          - drupal <unfixed> (embed)
152          - phpgroupware <unfixed> (embed)          - phpgroupware <unfixed> (embed)
153          - egroupware <unfixed> (embed)          - egroupware <unfixed> (embed)
154          - phpwiki (embed)          - phpwiki <unfixed> (embed)
155          - php4 <unfixed> (embed)          - php4 <unfixed> (embed)
156          TODO: check, php-pear, IIRC this was reorganized some weeks ago?          TODO: check, php-pear, IIRC this was reorganized some weeks ago?
157    
# Line 92  shtool (affects build-time only) Line 159  shtool (affects build-time only)
159          - mysql-ocaml <unfixed> (embed)          - mysql-ocaml <unfixed> (embed)
160          - php4 <unfixed> (embed)          - php4 <unfixed> (embed)
161    
162  mozilla source code  iceape
163          - mozilla-firefox <unfixed> (embed)          - iceweasel <unfixed> (fork)
164          - mozilla-thunderbird          - icedove <unfixed> (fork)
165          - firefox <removed>          - xulrunner <unfixed> (fork)
166          [etch] - firefox <unfixed> (embed)          - kompozer <unfixed> (embed; bug #532168)
         - thunderbird <removed>  
         [etch] - thunderbird <unfixed> (embed)  
         - iceweasel <unfixed> (embed)  
         - iceape <unfixed> (embed)  
         - icedove <unfixed> (embed)  
         - xulrunner <unfixed> (embed)  
         - nvu <removed> (embed)  
167    
168  xli  xli
169          - xloadimage <unfixed> (embed)          - xloadimage <unfixed> (embed)
170    
171  lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)  lesstif (beware: two different lesstif APIs supported in one package, MOTIF 1.2 discarded upstream)
172          - openmotif <unfixed> (embed)          - openmotif <unfixed> (embed)
173          - xfree86/xorg <unfixed> (embed)          - libxpm <unfixed> (embed)
         NOTE: in libxpm  
174    
175  kerberized apps with BSD origin  kerberized apps with BSD origin
176          - krb4 <unfixed> (embed)          - krb4 <removed> (embed)
177          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
178          - heimdal <unfixed> (embed)          - heimdal <unfixed> (embed)
179    
180  grip (which pkg is the origin?)  grip (which pkg is the origin?)
181          - libcdaudio          - libcdaudio <unfixed>
182          - grip          - grip <unfixed>
183          - gnome-vfs          - gnome-vfs <unfixed>
184          TODO: check vfs2 as well          TODO: check vfs2 as well
185    
186  fudforum  fudforum
187          - phpgroupware-fudforum <unfixed> (embed)          [etch] - phpgroupware <unfixed> (embed)
188          - egroupware-fudforum <removed>          NOTE: phpgroupware-fudforum
189          [sarge] - egroupware-fudforum <unfixed> (embed)          [sarge] - egroupware-fudforum <removed> (embed)
190    
191    libbsd
192            - rdate 1:1.2-3 (embed)
193            - atheme-services <unfixed>
194            - libbsd-arc4random-perl <unfixed>
195            - isakmpd <unfixed>
196    
197  cvs  cvs
198          - gcvs <unfixed> (embed)          - gcvs <unfixed> (embed)
199          NOTE: see cvsunix/src in tarball          NOTE: see cvsunix/src in tarball
200    
201  pcre  pcre3
         - python* <unfixed> (embed)  
202          - php4 <unknown> (embed)          - php4 <unknown> (embed)
203          - analog 2:5.23-0woody1 (embed)          - analog 2:5.23-0woody1 (embed)
204          - libgoffice-1 <unfixed> (embed)          - goffice <unfixed> (embed)
205            NOTE: libgoffice-*
206          - vfu 4.06-4.1 (embed; bug #450754)          - vfu 4.06-4.1 (embed; bug #450754)
207          - tf5 5.0beta7-1 (embed)          - tf5 5.0beta7-1 (embed)
208          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
209          NOTE: this only affects versions >= 0.37          NOTE: this only affects versions >= 0.37
210          - glib <unfixed> (embed)          - glib2.0 2.15.2-1 (embed)
         NOTE: 2.14 series for gregex support, only for udeb, regular packag links dynamic  
211          - apache2 2.0.53-4 (embed)          - apache2 2.0.53-4 (embed)
212          - exim4 4.10-0.srh20.12 (embed)          - exim4 4.10-0.srh20.12 (embed)
213          - yacas <unfixed> (embed)          - yacas <unfixed> (embed)
214          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway          NOTE: <= 1.0.x; is using pcre to scan text, can execute shell commands via the syntax anyway
215          - gtamsanalyzer.app 0.42-5 (embed)          - gtamsanalyzer.app 0.42-5 (embed)
216            - tin <unknown> (embed)
217            - kazehakase 0.5.2-1
218            - webkit 1.0.1-1 (embed)
219            - qt4-x11 <unfixed> (embed)
220            NOTE: embedded via webkit copy
221            - erlang <unfixed> (embed)
222    
223  tiff  tiff
224          - wxpythongtk <unfixed> (embed)          - wxwindows2.4 2.2.1 (embed)
225          TODO: check, which debian pkg this is in          - gamera 3.2.3-1 (embed)
226    
227  uudeview  uudeview
228          - libconvert-uulib-perl <unfixed> (embed)          - libconvert-uulib-perl <unfixed> (embed)
229            - pan <unfixed> (embed)
230    
231  sqlite (not affected by security vulnerabilities so far)  sqlite (not affected by security vulnerabilities so far)
232          - amarok <unfixed> (embed)          - amarok <unfixed> (embed)
233          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
234          - iceweasel <unfixed> (embed)          - iceweasel <unfixed> (embed)
235    
236  util-linux/mount  util-linux/mount
237          - loop-aes-utils <unfixed> (embed)          - loop-aes-utils <unfixed> (embed)
238          NOTE: contains code from util-linux' mount in the mount-aes-udeb          NOTE: contains code from util-linux' mount in the mount-aes-udeb
239    
 webmin  
         - usermin <unknown> (embed)  
         [sarge] - usermin <unfixed> (embed)  
   
240  sylpheed  sylpheed
241          - sylpheed-claws <unfixed> (fork)          - sylpheed-claws <unfixed> (fork)
242    
# Line 184  phpldapadmin Line 251  phpldapadmin
251  chmlib  chmlib
252          - kchmviewer <unknown> (embed)          - kchmviewer <unknown> (embed)
253    
254  libavcodec/libavformat (source: ffmpeg)  ffmpeg (libavcodec/libavformat)
255          - mplayer <unfixed> (embed; bug #395252)          - mplayer 1.0~rc2-14 (embed; bug #395252)
256          - xvidcap <unfixed> (embed)          - kino 1.0.0-1
257          - kino <unfixed> (static)          - vlc <not-affected> (Links dynamically since initial release)
258          - vlc <unfixed> (static)          - smilutils 0.3.0-10
259          - smilutils <unfixed> (static)          NOTE: smilutils likely fixed earlier, marking Etch's version as fixed
260          - motion <unfixed> (static)          - motion 3.1.19-1
261          - gst-ffmpeg <unfixed> (embed)          - gstreamer0.10-ffmpeg 0.10.3-2
262          - gstreamer0.10-ffmpeg <unfixed> (embed)          - xmovie <removed> (static)
         - xmovie <unfixed>  
263          TODO: gimp-gap (potentially using ffmpeg code as well)          TODO: gimp-gap (potentially using ffmpeg code as well)
264            - avifile 1:0.7.48~20090503.ds-1 (embed; bug #538750)
265    
266    faad2
267            - mplayer 1.0~rc2-20 (embed)
268            - avifile <unfixed> (embed; bug #538750)
269    
270  mad MPEG decoding lib  libmad (MPEG decoding lib)
         - mad <unfixed> (embed)  
271          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
272            - avifile 1:0.7.48~20090503.ds-1 (embed) [./plugins/libmad/*]
273            TODO: check ocaml-mad, madplay, pymad, xmms-mad, xmms2
274    
275  libdts  libdts
276          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
# Line 214  libmpeg2 Line 286  libmpeg2
286          - mpeg2dec <unfixed> (embed)          - mpeg2dec <unfixed> (embed)
287          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
288    
289  curl  libntlm
290          - wget <unfixed> (embed)          - wget <unfixed> (fork; bug #550436)
291          NOTE: code for NTLM authentication          - curl <unfixed> (fork; bug #550437)
292            - cntlm <unfixed> (fork; bug #550438)
293    
294  uw-imap  uw-imap
295          - pine <unfixed> (embed)          - pine <unfixed> (embed)
# Line 225  uw-imap Line 298  uw-imap
298  imagemagick  imagemagick
299          - graphicsmagick <unfixed> (fork)          - graphicsmagick <unfixed> (fork)
300    
301    python-urlgrabber
302            - mercurial <unfixed> (embed; bug #531062)
303            - w3af <unfixed> (embed)
304            [experimental] - harvestman <unfixed> (embed)
305    
306    beautifulsoup
307            - python-mechanize <unfixed> (embed)
308            - zope2.11 <unfixed> (embed)
309            - twill <unknown> (embed)
310    
311  halibut  halibut
312          - nsis <unfixed> (embed)          - nsis <unfixed> (fork)
313    
314  libghttp  libghttp
315          - hotway <unfixed> (embed)          - hotway <unfixed> (embed)
316    
317  libsndfile  libsndfile
318          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
319    
320  glibmm2.4  glibmm2.4
321          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
322    
323  libgnomecanvasmm2.6  libgnomecanvasmm2.6
324          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
325    
326  libsigc++-2.0  libsigc++-2.0
327          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
328    
329  soundtouch  soundtouch
330          - ardour <unfixed> (embed)          - ardour 1:2.7.1-1 (embed)
331    
332  libmms  libmms
333          - xine-lib <unfixed> (embed)          - xine-lib <unfixed> (embed)
334          - mimms <unfixed> (embed)          - mimms <unfixed> (embed)
335    
336  fckeditor  fckeditor
337          - knowledgeroot <unfixed> (embed)          - knowledgeroot 0.9.8.5-3 (embed; bug #461555)
338          - moin <unfixed> (embed; bug #452599)          - moin 1.8.2-2 (embed; bug #452599)
339          - karrigell <unfixed> (embed; bug #452598)          - karrigell <removed> (embed; bug #452598)
340          - gforge-plugins-extra 4.6.99+svn6225-1 (embed)          - gforge 4.6.99+svn6225-1 (embed)
341            - request-tracker3.8 <unfixed> (embed)
342    
343  ipatlas (not packaged in Debian)  ipatlas (not packaged in Debian)
344          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
345    
346  libphp-phpmailer  libphp-phpmailer
347          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
348            - mahara <unfixed> (embed)
349            - symfony <unfixed> (embed)
350            [etch] - phpgroupware <unfixed> (embed)
351            NOTE: phpgroupware-felamimail is only in etch
352            - egroupware <unfixed> (embed; bug #504283)
353            - glpi <unfixed>
354    
355  htmlArea (not packaged in Debian)  htmlArea (not packaged in Debian)
356          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
357    
358  bennu (not packaged in Debian)  giflib
359          - moodle <unfixed> (embed)          - wine <unfixed> (embed; bug #466181)
360    
361  smarty:  bennu (not packaged in Debian, http://bennu.sourceforge.net)
362          - moodle <unfixed> (embed)          - moodle <unfixed> (embed)
363    
364    smarty
365            - moodle 1.8.2-2 (embed; bug #471158)
366            - gallery2 2.2.5-2 (embed; bug #471160)
367            - mahara 0.9.2-2 (embed; bug #471201)
368            - gosa 2.4beta1-1 (embed; bug #471200)
369    
370  TinyMCE  TinyMCE
371          - wordpress <unfixed> (embed)          - wordpress 2.5.1-3 (embed; bug #478257)
372          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
373          - knowledgeroot <unfixed> (embed)          - knowledgeroot <unfixed> (embed)
374          - joomla <itp> (bug #326398)          - joomla <itp> (bug #326398)
375    
376  scintilla  scintilla (upstream provides static lib, rejected shared lib http://sf.net/support/tracker.php?aid=2488121)
377          - scite <unfixed> (embed)          - scite <unfixed> (embed)
378          - qscintilla <unfixed> (embed)          - qscintilla <unfixed> (embed)
379          - qscintilla2 <unfixed> (embed)          - qscintilla2 <unfixed> (embed)
380          - geany <unfixed> (embed)          - geany <unfixed> (fork)
381            - anjuta <unfixed> (embed)
382    
383  libphp-adodb  libphp-adodb
384          - moodle <unfixed> (embed)          - moodle <unfixed> (embed; bug #507185)
385          NOTE: also AdoDB-XML Schema          NOTE: also AdoDB-XML Schema
386          - gallery2 <unfixed> (embed)          - gallery2 <unfixed> (embed)
387          - phppgadmin <unfixed> (embed)          - phppgadmin <unfixed> (embed)
388          - egroupware <unfixed> (embed)          - egroupware <unfixed> (embed)
389          - phpwiki <unfixed> (embed)          - phpwiki <unfixed> (embed)
390            - torrentflux 2.0beta1-2 (embed)
391          - ipplan <unfixed> (embed)          - ipplan <unfixed> (embed)
392          - typo3 <unfixed> (embed)          - typo3-src <unfixed> (embed)
         - moodle <unfixed> (embed)  
393          - cacti <unknown> (embed)          - cacti <unknown> (embed)
394          [sarge] - cacti <unfixed> (embed)          [sarge] - cacti <unfixed> (embed)
395          NOTE: dependency exists, but internal version is used          NOTE: dependency exists, but internal version is used
396            - gforge 4.7~rc2-6 (embed)
397            - mahara <unfixed> (embed)
398    
399  gzip  gzip
400          - linux-kernel <unfixed> (embed)          - linux-kernel <unfixed> (embed)
# Line 305  gzip Line 404  gzip
404          - busybox <unfixed> (embed)          - busybox <unfixed> (embed)
405    
406  neon  neon
407          - cadaver <unfixed> (embed; bug #188381)          - cadaver 0.22.3+debian-1 (embed; bug #188381)
408          - gnome-vfs2 <unfixed> (embed; bug #395874)          - gnome-vfs2 <unfixed> (embed; bug #395874)
409          - litmus <unfixed> (embed; #395875)          [etch] - litmus <unfixed> (embed; #395875)
410            - litmus <removed> (embed; #395875)
411          [sarge] - screem <unfixed> (embed)          [sarge] - screem <unfixed> (embed)
412          - sitecopy <unfixed> (embed; bug #395876)          - sitecopy 1:0.16.3-5 (embed; bug #395876)
413          [etch] - tla <unfixed> (embed; bug #395877)          [etch] - tla <unfixed> (embed; bug #395877)
414          [sarge] - tla <unfixed> (embed; bug #395877)          [sarge] - tla <unfixed> (embed; bug #395877)
415    
# Line 328  tinyxml (not packaged in Debian) Line 428  tinyxml (not packaged in Debian)
428  gv  gv
429          - evince <unfixed> (embed)          - evince <unfixed> (embed)
430          NOTE: ps/ tree from gv 3.5.8          NOTE: ps/ tree from gv 3.5.8
431          - evince-gtk <unfixed> (embed)          NOTE: evince-gtk is affected (a component of evince source package)
         NOTE: not packaged in Debian  
432    
433  libXbae  libXbae
434          [etch] - libpawlib2-lesstif <unfixed> (embed)          - paw <removed> (embed)
435          NOTE: from Cernlib          [etch] - paw <unfixed> (embed)
436    
437    libgtkhtml
438            - claws-mail-extra-plugins <unfixed> (fork)
439    
440  libXaw  libXaw
441          [etc] - libpawlib2-lesstif          - paw <removed> (embed)
442          NOTE: from Cernlib          [etch] - paw <unfixed> (embed)
443          NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty          NOTE: I plan to deal with the above two cases after Etch release. -- KevinMcCarty
444    
445  libgd2  libgd2
446          - graphviz <unfixed> (embed)          - graphviz <unfixed> (embed)
447          NOTE: lib/gd seems to be 2.0.33          NOTE: lib/gd seems to be 2.0.33
448            - wml <unfixed> (embed)
449            - libwmf <unfixed> (embed)
450            NOTE: derived from gd 1.6.3
451    
452  rar  rar
453          - unrar-nonfree <unfixed> (embed)          - unrar-nonfree <unfixed> (embed)
# Line 356  mplayer (DirectMedia Object loader) Line 461  mplayer (DirectMedia Object loader)
461          NOTE: src/libw32dll/          NOTE: src/libw32dll/
462          - vlc <unfixed> (embed)          - vlc <unfixed> (embed)
463          NOTE: modules/codec/dmo/          NOTE: modules/codec/dmo/
464            - mplayer 1.0~rc2-20 (embed)
465    
466  libwpd (WordPerfect converter)  libwpd (WordPerfect converter)
467          - openoffice.org <unfixed> (embed)          - openoffice.org <unfixed> (embed)
# Line 364  fsplib (http://sourceforge.net/projects/ Line 470  fsplib (http://sourceforge.net/projects/
470          - gftp <unfixed> (embed)          - gftp <unfixed> (embed)
471          NOTE: lib/fsplib version 0.3          NOTE: lib/fsplib version 0.3
472    
473    sprng
474            - tree-puzzle <unfixed> (embed)
475    
476  librpcsecgss  librpcsecgss
477          - krb5 <unfixed> (embed)          - krb5 <unfixed> (embed)
478    
# Line 371  jasper Line 480  jasper
480          - ghostscript <unfixed> (embed)          - ghostscript <unfixed> (embed)
481          - gs-gpl <unfixed> (embed)          - gs-gpl <unfixed> (embed)
482    
483    libiris
484            - psi <unfixed> (embed)
485            - kdenetwork <unfixed> (embed)
486            NOTE: kopete embeds libiris but links dynamically to libidn
487            - kdegames <unfixed> (embed)
488            NOTE: ksirk/kde4
489    
490  libidn  libidn
491          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
492            - psi <unfixed> (embed)
493            NOTE: psi embeds libiris which embeds libidn
494            - kdegames <unfixed> (embed)
495            NOTE: kdegames/kde4 embeds libiris which embeds libidn
496    
497  liblua  liblua
498          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
499            - nmap 5.00-1 (embed; bug #527997)
500            [lenny] - nmap <unfixed> (embed; bug #527997)
501    
502  libbotan  libbotan
503          - montone <unfixed> (embed)          - monotone 0.43-1 (embed)
504    
505  NetXX  NetXX
506          - monotone <unfixed> (embed)          - monotone 0.43-1 (embed)
507    
508  libgc  libgc
509          - mono <unfixed> (embed)          - mono <unfixed> (embed)
510    
511  lzma  lzma
512          - p7zip <unfixed> (embed)          - p7zip <unfixed> (embed)
513            - xz-utils <unfixed> (fork)
514    
515  lzo  lzo
516          - grub2 <unfixed> (embed)          - grub2 <unfixed> (embed)
517    
518    yassl
519            - mysql-dfsg-5.0 <unfixed> (embed)
520    
521  pax code  pax code
522          - tar <unfixed> (embed)          - tar <unfixed> (embed)
523          - cpio <unfixed> (embed)          - cpio <unfixed> (embed)
# Line 399  pax code Line 525  pax code
525  t1lib  t1lib
526          - tetex-bin 2.0.2-1 (embed)          - tetex-bin 2.0.2-1 (embed)
527          - texlive-bin <unknown> (embed)          - texlive-bin <unknown> (embed)
528    
529    guichan
530            - boswars <unfixed> (embed)
531            NOTE: maintainer notified us, working on it
532    
533    tolua
534            - boswars <unfixed> (embed)
535            NOTE: maintainer notified us, working on it
536    
537    asio-dev
538            - luxrender <removed> (embed)
539    
540    xine-lib
541            - vlc <unfixed> (embed)
542            NOTE: only parts included in modules/access/rtsp
543    
544    netpbm
545            - tcl8.3 <unfixed> (embed)
546            - tcl8.4 <unfixed> (embed)
547            - tcl8.5 <unfixed> (embed)
548            NOTE: generic/tkImgGIF.c
549    
550    tk8.5
551            - tk8.0 <removed> (old-version)
552            - tk8.3 <unfixed> (old-version)
553            - tk8.4 <unfixed> (old-version)
554            - perl-tk <unfixable> (fork)
555    
556    samba
557            - mc 2:4.6.2~git20080311-1 (embed)
558            NOTE: maintainer is aware of this, currently searching a solution
559    
560    plib1.8.4c2
561            - boson <unfixed> (fork)
562            NOTE: embedding the font pieces of plib, based on the header file it is forked, contains "Added by AB for boson." and similar
563    
564    fribidi
565            - quesoglc <unfixed> (embed)
566            NOTE: compiled against system fribidi in Debian - embed only used when fribidi is not available on the system
567    
568    glew
569            - quesoglc <unfixed> (embed; bug #489341)
570            NOTE: waiting on GLEW_MX version of glew (see bug #474488)
571    
572    minorGems (pabs contacted upstream about shared lib, he considers minorGems an 'ever-evolving collection of reusable code fragments' for his own use)
573            - transcend <unfixed> (embed)
574            - cultivation <unfixed> (embed)
575            - passage <unfixed> (embed)
576            - gravitation <unfixed> (embed)
577    
578    tar
579            - libarchive <unfixed> (embed)
580            NOTE: FreeBSD tar (tar/bsdtar.c) in libarchive 1.2 and higher. libarchive ends up statically linked into bsdtar executable
581    
582    cpio
583            - libarchive <unfixed> (embed)
584            NOTE: cpio included in libarchive 2.2 and higher, but not compiled until libarchive 2.4.11-1 (as bsdcpio package)
585    
586    webkit
587            - qt4-x11 <unfixed> (embed)
588    
589    ftgl
590            - blender 2.46+dfsg-1 (embed)
591    
592    wv
593            - abiword <unfixed>
594    
595    qemu
596            - kvm <unfixed> (embed; bug #543159)
597            - xen-3 <unfixed> (embed)
598            - xen-unstable <unfixed> (embed)
599    
600    vgabios
601            - kvm <unfixed> (embed; bug #489442)
602    
603    bochs
604            - kvm <unfixed> (embed; bug #489442)
605    
606    speex
607            - vorbis-tools <unfixed> (embed)
608            NOTE: while comiled against libspeex-dev, ogg123/speex_format.c is compiled with embedded code copied from speexdec.c
609            - gst-plugins-good0.10 <unfixed> (embed)
610            - xine-lib <unfixed> (embed)
611            - libfishsound <unfixed> (embed)
612            - libannodex <unfixed> (embed)
613            - vlc <unfixed> (embed)
614            - xmms-speex <unfixed> (embed)
615            - libsdl-sound1.2 <unfixed> (embed)
616            - sweep <unfixed> (embed)
617    
618    libreadline
619            - magic <itp> (old-version)
620    
621    opcode
622            - ode <unfixed> (embed)
623            NOTE: opcode is not a package in debian, it is just embedded
624            NOTE: http://www.codercorner.com/Opcode.htm
625    
626    gimpact
627            - ode <unfixed> (embed)
628            NOTE: gimpact is not a package in debian, it is just embedded
629            NOTE: http://gimpact.sf.net
630    
631    mochikit
632            - mahara <unfixed> (embed)
633            NOTE: they require extra patches, still unmerged upstream
634            - ntop <unfixed> (embed)
635            - coherence 0.6.2-1 (embed)
636            - paste <unfixed> (embed)
637            - turbogears <unfixed> (embed)
638            - plone3 <unfixed> (embed)
639            - xulrunner <unfixed> (embed)
640            - libjifty-plugin-chart-perl <unfixed> (embed)
641            - sabnzbdplus <unfixed> (embed)
642            - tgmochikit <unfixed> (embed)
643    
644    prototypejs
645            - netbeans-ide 6.0.1+dfsg-2 (embed)
646            - auth2db <unfixed> (embed)
647            - webcit <unfixed> (embed)
648            - asterisk 1:1.6.2.0~rc3-1 (embed)
649            - doc-iana <unfixed> (embed)
650            - libaws <unfixed> (embed)
651            - libjson-ruby <unfixed> (embed)
652            - lucene2 <unfixed> (embed)
653            - solr <unfixed> (embed)
654            - glpi <unfixed> (embed)
655            - mnemo2 <unfixed> (embed)
656            - nag2 <unfixed> (embed)
657            - knowledgeroot <unfixed> (embed)
658            - mediatomb <unfixed> (embed)
659            - mt-daapd 0.9~r1696.dfsg-6lenny2 (embed)
660            - op-panel <unfixed> (embed)
661            - ebug-http <unfixed> (embed)
662            - phpgedview <removed> (embed)
663            - poker-network <unfixed> (embed)
664            - webhelpers <unfixed> (embed)
665            - qwik <unfixed> (embed)
666            - rails 2.1.0-6 (embed)
667            - typo3-src <unfixed> (embed)
668            - wordpress 2.5.0-2 (embed)
669            - zope <unfixed> (embed)
670            - smokeping 2.3.6-3 (embed)
671            - ampache 3.4.1-2 (embed)
672            - exaile <unfixed> (embed)
673            - hobix <unfixed> (embed)
674            - pixelpost <unfixed> (embed)
675            - symfony <unfixed> (embed)
676            NOTE: it's been said that there are custom changes
677            - zabbix <unfixed> (embed)
678            - turba2 <unfixed> (embed)
679            - chora2 <unfixed> (embed)
680            - gollem <unfixed> (embed)
681            - jscropperui <unfixed> (embed)
682            - rt-extension-emailcompletion <unfixed> (embed)
683            - scriptaculous <unfixed> (embed)
684            - ingo1 <unfixed> (embed)
685            - kronolith2 <unfixed> (embed)
686            - libpdfbox-java <unfixed> (embed)
687            - activeldap <unfixed> (embed)
688            - libfontbox-java <unfixed> (embed)
689            - libjempbox-java <unfixed> (embed)
690            - libv8 <unfixed> (embed)
691            - mantis <unfixed> (embed)
692            - otrs2 <unfixed> (embed)
693            - webcalendar <unfixed> (embed)
694            - redmine <unfixed> (embed)
695            - jifty <unfixed> (embed)
696            - jquery <unfixed> (embed)
697            - passenger <unfixed> (embed)
698            - plone3 <unfixed> (embed)
699            - pylucene <unfixed> (embed)
700            - request-tracker3.6 <unfixed> (embed)
701            - request-tracker3.8 <unfixed> (embed)
702            - wesnoth <unfixed> (embed)
703            - xulrunner <unfixed> (embed)
704            NOTE: included in iceweasel/xulrunner unit tests directory, so may not be security-relevant
705    
706    gdb
707            - insight <unfixed> (embed)
708    
709    e2fsprogs
710            - ldiskfsprogs <unfixable> (fork)
711    
712    quazip (not packaged in Debian)
713            - qcake <unfixed> (embed)
714            NOTE: starting with upstream version 0.6.4
715    
716    exo
717            - pcmanfm <unfixed> (embed; bug #499677)
718            NOTE: slightly modified source code
719    
720    java
721            - openjdk-6 <unfixed>
722            - sun-java5 <unfixed>
723            - sun-java6 <unfixed>
724    
725    libphp-snoopy
726            - ampache 3.4.1-2 (embed; bug #504169)
727            - mahara 1.0.5-2 (embed; bug #504170)
728            - pixelpost 1.7.1-5 (embed; bug #504171)
729            - mediamate 0.9.3.6-5 (embed; bug #504172)
730            - opendb <removed> (embed; bug #504173)
731            [etch] - opendb <unfixed> (embed; bug #504173)
732            - wordpress 2.5.1-9 (embed; bug #443948)
733            - moodle <unfixed> (embed; bug #507185)
734            [etch] - phpgroupware <unfixed> (embed)
735            NOTE: phpgroupware-felamimail
736            - magpierss 0.72-3 (embed; bug #431089)
737    
738    jquery
739            - zekr <unfixed> (embed)
740            - wordpress <unknown> (embed)
741            - yocto-reader <unfixed> (embed)
742            - textpattern <unfixed> (embed)
743            - genshi 0.5.1-1 (embed)
744            NOTE: compressed file under examples/ dir
745            - prewikka <unfixed> (embed)
746            - libramaze-ruby <unfixed> (embed)
747            - drupal5 <unfixed> (embed)
748            - b2evolution <unfixed> (embed)
749            - wesnoth <unfixed> (embed)
750    
751    tablesorter (jquery plugin, not packaged yet)
752            - wesnoth <unfixed> (embed)
753    
754    kses
755            - wordpress <unfixed> (embed; bug #504242)
756            NOTE: their copy has all methods renamed to wp_<foo>
757            NOTE: kses isn't in Debian, RFP: #504240
758            - moodle <unfixed> (embed; bug #507185)
759            - egroupware <unfixed> (embed)
760    
761    magpierss
762            - wordpress <unfixed> (embed; bug #504242)
763            - moodle <unfixed>
764    
765    php-gettext
766            - wordpress 2.8.4-1 (embed; bug #504242)
767    
768    libphp-ixr (name may change, it is the Incutio XML-RPC)
769            - wordpress <unfixed> (embed; bug #504242)
770            NOTE: libphp-ixr isn't in Debian, RFP: #504236
771            - dokuwiki <unfixed> (embed)
772            - textpattern <unfixed> (embed)
773    
774    libphp-cas
775            - glpi <unfixed> (embed)
776            - moodle <unfixed> (embed; bug #505984)
777    
778    scriptaculous
779            - glpi <unfixed> (embed)
780            - libaws <unfixed> (embed)
781            NOTE: libaws-doc
782            - op-panel <unfixed> (embed)
783            - symfony <unfixed> (embed)
784            NOTE: maintainer says there are extra incompatible changes required
785            - pixelpost <unfixed> (embed)
786            - webhelpers <unfixed> (embed)
787            NOTE: python-webhelpers
788            - qwik <unfixed> (embed)
789            - smokeping <unfixed> (embed)
790            - turba2 <unfixed> (embed)
791            - typo3-src 4.2.3-1 (embed)
792            - request-tracker3.6 <unfixed> (embed)
793            - request-tracker3.8 <unfixed> (embed)
794    
795    libmarkdown-php
796            - moodle <unfixed> (embed; bug #507185)
797            - pixelpost <unfixed> (embed)
798    
799    php-openid
800            - wordpress-openid <itp> (embed)
801    
802    geshi
803            - dokuwiki 0.0.20080505-3.1 (embed)
804            - pgfouine 1.0-1.1 (embed)
805            - websvn 2.1.0-1 (embed)
806    
807    webcalendar
808            - gforge 4.7~rc2-6 (embed; bug #504758)
809    
810    libical
811            - kdepim <unfixed> (fork)
812            - kdepimlibs <unfixed> (fork)
813            NOTE: fixed in KDE4 post 4.1.x series
814            - claws-mail-extra-plugins <unfixed> (fork)
815    
816    libltdl3
817            - kdelibs <unfixed> (embed)
818            NOTE: it's been said it sets RT_GLOBAL (or something like that) at runtime and version in experimental of libltdl can optionally set it
819            - synfig <unfixed> (embed)
820    
821    harfbuzz
822            - qt4-x11 <unfixed> (embed)
823    
824    libzip
825            - php5 <unfixed> (fork)
826            - odt2txt <unfixed> (embed; bug #523808)
827    
828    json.php (not packaged; should be replaced with php's built-in functions)
829            - moodle <unfixed>
830            - yui <unfixed>
831            - gallery2 <unfixed>
832            - dokuwiki <unfixed>
833            - typo3-src <unfixed>
834    
835    php-fpdf
836            - tcpdf <itp> (fork)
837            - moodle <unfixed>
838            - phpwiki <unfixed>
839            - egroupware <unfixed>
840            - ldap-account-manager <unfixed> (fork)
841    
842    tcpdf (itp: #495985)
843            - moodle <unfixed>
844            - phpmyadmin <unfixed>
845    
846    typo3
847            - moodle <unfixed>
848    
849    spreadsheet_writeexcel (PHP port of libspreadsheet-writeexcel-perl; itp: #487557)
850            - moodle <unfixed>
851            - gosa <unfixed>
852    
853    php-ole (itp: #487558)
854            - moodle <unfixed>
855    
856    pieforms (http://www.catalyst.net.nz)
857            - mahara <unfixed>
858    
859    savant2 (http://phpsavant.com)
860            - egroupware <unfixed>
861    
862    rssparser (http://nwow.org)
863            - egroupware <unfixed>
864            - phpgroupware <unfixed>
865    
866    lcms
867            - openjdk-6 <unfixed> (fork)
868    
869    libphp-phplayersmenu
870            - diogenes <unfixed>
871            - phpldapadmin <unfixed>
872    
873    libphp-pclzip
874            - docvert <unfixed>
875            - moodle <unfixed>
876            - egroupware <unfixed>
877    
878    libphp-simplepie
879            - dokuwiki <unfixed>
880    
881    libphp-jpgraph
882            - egroupware <unfixed>
883    
884    php-simpletest
885            - moodle <unfixed>
886    
887    libpng
888            - iceweasel <not-affected> (uses xulrunner)
889            - icedove 1.5.0.13+1.5.0.15b.dfsg1+prepatch080614i-0etch1, 2.0.0.19-1 (embed)
890            - iceape 1.0.13~pre080614i-0etch1 (embed)
891            - xulrunner 1.9.0.13-1 (embed)
892            [lenny] - xulrunner 1.9.0.11-0lenny1
893            [etch] - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
894            - gamera 3.2.3-1 (embed)
895    
896    irssi
897            - silc-client <unfixed> (embed)
898            NOTE: Seems to be a pre-0.8.12 version that is used in irssi-plugin-silc
899    
900    extc
901            - mtasc <unfixed> (embed)
902            - haxe <unfixed> (embed)
903    
904    swflib
905            - mtasc <unfixed> (embed)
906            - haxe <unfixed> (embed)
907    
908    libitext-java
909            - bouncycastle 2.1.4-1 (embed)
910    
911    python-ply
912            - pyke <unfixed> (embed)
913            - pywbem <unfixed> (embed)
914            - sepolgen <unfixed> (embed)
915            - zope-textindexng3 <unknown> (embed)
916            - iceweasel <unknown> (embed)
917            - xulrunner <unknown> (embed)
918            - wireshark <not-affected> (embed)
919    
920    libdumbnet (libdnet upstream)
921            - nmap <unfixed> (fork)
922    
923    gcc-4.4
924            - gcc-mingw32 <unfixed> (embed)
925    
926    camlimages
927            - advi <unfixed> (static; bug #550441)
928    
929    memcached
930            - memcachedb <unfixed> (embed)
931    
932    yajl
933            - argyll <unfixed> (embed; bug #544223)
934            NOTE: reference, confirmed by build logs: http://lists.debian.org/debian-mentors/2009/08/msg00062.html
935    
936    libept
937            - adept <unfixed> (embed; bug #540649)
938    
939    libvorbis
940            - iceweasel <not-affected> (uses xulrunner)
941            - xulrunner <unfixed> (embed; bug #540959)
942            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
943            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
944    
945    cairo
946            - iceweasel <not-affected> (uses xulrunner)
947            - xulrunner 1.8.0.15~pre080614i-0etch1 (embed)
948    
949    liboggz
950            - iceweasel <not-affected> (uses xulrunner)
951            - xulrunner <unfixed> (embed; bug #540949)
952            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
953            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
954    
955    
956    liboggplay
957            - iceweasel <not-affected> (uses xulrunner)
958            - xulrunner <unfixed> (embed; bug #540949)
959            [etch] - xulrunner <not-affected> (introduced in firefox 3.5)
960            [lenny] - xulrunner <not-affected> (introduced in firefox 3.5)
961    
962    php-net-dnsbl
963            - serendipity <unfixed> (embed)
964    
965    php-onyx-rss
966            - serendipity <unfixed> (embed)
967    
968    php-text-wiki
969            - serendipity <unfixed> (embed)
970    
971    php-xml-rpc
972            - serendipity <unfixed> (embed)
973    
974    polarssl (does not have a shared library)
975            - pdkim <itp> (embed; bug #543150)
976            - xyssl <unfixed> (old-version)
977    
978    pidgin
979            - gaim <removed> (old-version)
980    
981    icu
982            - webkit 1.0.1-1 (embed; bug #547214)
983            - texlive-bin <unfixed> (fork)
984            NOTE: texlive upstream working with icu upstream to merge their changes
985    
986    cyrus-imapd-2.2
987            - kolab-cyrus-imapd <unfixed> (fork)
988            - dovecot 1:1.2.1-1 (embed) [/dovecot-sieve/src/libsieve/*]
989    
990    python-cxx-dev
991            - freecad <unfixed> (embed; bug #547936)
992    
993    libzipios++-dev
994            - freecad <unfixed> (embed; bug #547941)
995    
996    linux-2.6
997            - kvm <unfixed> (embed; bug #549973) [./kernel/*]
998            - linux-kbuild-2.6 <unfixed> (embed; bug #550379) [./kbuild/*]
999            - kernel-source-2.6.8 <removed> (old-version)
1000            - kernel-source-2.4.27 <removed> (old-version)
1001            - kernel-source-2.4.24 <removed> (old-version)
1002            - kernel-source-2.2.25 <removed> (old-version)
1003            - kernel-source-2.2.20 <removed> (old-version)
1004    
1005    libfdt (not yet packaged separately for debian; http://www.jdl.com/software/)
1006            - kvm <unfixed> (embed) [./libfdt/*]
1007    
1008    qweb (not packaged)
1009            - ajaxterm <unfixed>
1010    
1011    opensaml2
1012            - opensaml <removed> (old-version)
1013    
1014    shibboleth-sp2
1015            - shibboleth-sp <removed> (old-version)
1016    
1017    tuxonice-userui
1018            - suspend2-userui <removed> (old-version)
1019    
1020    expat
1021            - w3c-libwww <removed> (embed; bug #551941)
1022            [etch] - w3c-libwww <unfixed> (embed; bug #551941) [./modules/expat/*]
1023            - python-xml <unfixed> (embed; bug #551940) [./extensions/expat/*]
1024            - python2.5 <unfixed> (embed; bug #553403) [./Modules/expat/*]
1025            - python2.4 <unfixed> (embed; bug #553403)
1026            - wxwindows2.4 <removed> (embed)
1027            - wxwidgets2.6 <unfixed> (embed)
1028            - wxwidgets2.8 <unfixed> (embed)
1029            - celementtree <unfixed> (embed)
1030            - audacity <unfixed> (embed)
1031            - matanza <unfixed> (embed)
1032            - tdom <unfixed> (embed)
1033            - udunits <unfixed> (embed)
1034            - apr-util 1.2 (embed)
1035            - ayttm <unfixed> (embed)
1036            - cableswig <unfixed> (embed)
1037            - cadaver <unfixed> (embed)
1038            - cmake <unfixed> (embed)
1039            - coin3 <unfixed> (embed)
1040            - gdcm <unfixed> (embed)
1041            - ghostscript <unfixed> (embed)
1042            - grmonitor <unfixed> (embed)
1043            - iceape <unfixed> (embed)
1044            - insighttoolkit <unfixed> (embed)
1045            - libparagui1.1 <unfixed> (embed)
1046            - paraview <unfixed> (embed)
1047            - poco <unfixed> (embed)
1048            - simgear <unfixed> (embed)
1049            - sitecopy <unfixed> (embed)
1050            - smart 1.0-1 (embed)
1051            [etch] - smart <unfixed> (embed)
1052            - swish-e <unfixed> (embed)
1053            - tla <unfixed> (embed)
1054            - vtk <unfixed> (embed)
1055            - wbxml2 <unfixed> (embed)
1056            - xmlrpc-c <unfixed> (embed)
1057            - iceweasel <unfixed> (embed)
1058            - kompozer <unfixed> (embed)
1059            - vxl <unfixed> (embed)
1060            - xulrunner <unfixed> (embed)
1061            - apache2 2.2 (embed)
1062            - texlive-bin <unfixed> (embed) [included twice]
1063            - vnc4 <unfixed> (embed)
1064            - xotcl <unfixed> (embed)
1065    
1066    xerces-c
1067            - xerces-c2 <unfixed> (old-version)
1068            - xerces27 <removed> (old-version)
1069    
1070    md5 (RSA's version; not the gnu version provided by coreutils)
1071            - w3c-libwww <removed> (embed; bug #551942)
1072            [etch] - w3c-libwww <unfixed> (embed; bug #551942) [./modules/md5/*]
1073    
1074    enet
1075            - sauerbraten <unfixed> (embed; #497194)
1076    
1077    eglibc
1078            - glibc <removed> (old-version)
1079    
1080    galib
1081            - gamera 3.2.3-1 (embed)
1082    
1083    configobj
1084            - bzr <unfixed> (embed)
1085            - elisa <unfixed> (embed)
1086            - gaupol <unfixed> (embed)
1087            - ipython <unfixed> (embed)
1088            - pida <unfixed> (embed)
1089            - psychopy <unfixed> (embed)
1090            - rest2web <unfixed> (embed)
1091            - auth2db <unknown> (embed)
1092            - dynagen <unknown> (embed)
1093            - iceweasel <unknown> (embed)
1094            - sabnzbdplus <unknown> (embed)
1095            - xulrunner <unknown> (embed)
1096            - nipy <not-affected> (embed) [./examples/neurospin/neurospy/configobj.py]
1097    
1098    python-clientform
1099            - bibus <unfixed> (embed)
1100            - zope2.10 <unfixed> (embed)
1101            - zope2.11 <unfixed> (embed)
1102            - python-mechanize <unknown> (embed)
1103            - twill <unknown> (embed)
1104    
1105    python-mechanize
1106            - zope2.10 <unfixed> (embed)
1107            - zope2.11 <unfixed> (embed)
1108            - twill <unknown> (embed)
1109    
1110    pexpect
1111            - duplicity <unfixed> (embed)
1112            - hplip <unfixed> (embed)
1113            - smart <unfixed> (embed)
1114    
1115    pyparsing
1116            - bauble <unfixed> (embed)
1117            - boa-constructor <unfixed> (embed)
1118            - calibre <unfixed> (embed)
1119            - matplotlib <unfixed> (embed)
1120            - zhpy <unfixed> (embed)
1121            - polybori <unknown> (embed)
1122            - python-whoosh <unknown> (embed)
1123            - twill <unknown> (embed)
1124            - zope-textindexng3 <unknown> (embed)
1125    
1126    python-pysqlite2
1127            - python2.4 <unfixed> (embed; bug #553403)
1128            - python2.5 <unfixed> (embed; bug #553403)
1129    
1130    celementtree
1131            - python2.5 <unfixed> (embed)
1132            - smart 1.0-1 (embed)
1133            [etch] - smart <unfixed> (embed)
1134    
1135    elementtree
1136            - python2.5 <unfixed> (embed)
1137            - bzr <unfixed> (embed)
1138            - gedit <unfixed> (embed)
1139            - smart 1.0-1 (embed)
1140            [etch] - smart <unfixed> (embed)
1141            - solfege <unfixed> (embed)
1142            - w3af <unfixed> (embed)
1143            - python-qt4 <unknown> (embed)
1144            - sphinx <unknown> (embed)
1145            - python-nltk <itp> (embed)
1146    
1147    python2.5
1148            - python2.4 <unfixed> (old-version)
1149            - jython <unfixed> (embed)
1150            NOTE: embeds many stdlib modules
1151            - python-django <unfixed> (embed)
1152            NOTE: embeds stdlib modules: doctest, decimal
1153            - gamera 3.2.3-1 (embed)
1154            NOTE: embeds stdlib modules: ConfigParser, optparse, sets, textwrap
1155            - boa-constructor <unfixed> (embed)
1156            NOTE: embeds stdlib modules: ConfigParser
1157            - nicotine <unfixed> (embed)
1158            NOTE: embeds stdlib modules: ConfigParser
1159            - museek+ <unfixed> (embed)
1160            NOTE: embeds stdlib modules: ConfigParser
1161            - vegastrike-data <unfixed> (embed)
1162            NOTE: embeds many stdlib modules
1163            - codespeak-lib <unfixed> (embed)
1164            NOTE: embeds stdlib modules: doctest, optparse, subprocess, textwrap
1165            - config-manager <unfixed> (embed)
1166            NOTE: embeds stdlib modules: optparse
1167            - jhbuild <unfixed> (embed)
1168            NOTE: embeds stdlib modules: optparse, subprocess
1169            - smart <unfixed> (embed)
1170            NOTE: embeds stdlib modules: optparse
1171            - pyprotocols <unfixed> (embed)
1172            NOTE: embeds stdlib modules: doctest
1173            - ruledispatch <unfixed> (embed)
1174            NOTE: embeds stdlib modules: doctest
1175            - distribute <unfixed> (embed)
1176            NOTE: embeds stdlib modules: doctest
1177            - python-setuptools <unfixed> (embed)
1178            NOTE: embeds stdlib modules: doctest
1179            - zope.testing <unfixed> (embed)
1180            NOTE: embeds stdlib modules: doctest
1181            - translate-toolkit <unfixed> (embed)
1182            NOTE: embeds stdlib modules: textwrap, contextlib
1183            - libtpclient-py <unfixed> (embed)
1184            NOTE: embeds stdlib modules: subprocess
1185            - grass <unfixed> (embed)
1186            NOTE: embeds stdlib modules: subprocess
1187            - coherence <unfixed> (embed)
1188            NOTE: embeds stdlib modules: uuid
1189            - python-django-extensions <unfixed> (embed)
1190            NOTE: embeds stdlib modules: uuid
1191            - setroubleshoot <unfixed> (embed)
1192            NOTE: embeds stdlib modules: uuid
1193            - linkchecker <unfixed> (embed)
1194            NOTE: embeds msgfmt.py script
1195            - imdbpy <unfixed> (embed)
1196            NOTE: embeds msgfmt.py script
1197            - kiwi <unfixed> (embed)
1198            NOTE: embeds msgfmt.py script
1199            - moin <unfixed> (embed)
1200            NOTE: embeds msgfmt.py script
1201            - plone3 <unfixed> (embed)
1202            NOTE: embeds msgfmt.py script
1203            - roundup <unfixed> (embed)
1204            NOTE: embeds msgfmt.py script
1205            - rednotebook <unfixed> (embed)
1206            NOTE: embeds msgfmt.py script
1207            - turbogears <unfixed> (embed)
1208            NOTE: embeds msgfmt.py script
1209            - elisa <unfixed> (embed)
1210            NOTE: embeds msgfmt.py script, stdlib modules: uuid
1211            - calibre <unfixed> (embed)
1212            NOTE: embeds msgfmt.py script
1213            - mailman <unfixed> (embed)
1214            NOTE: embeds msgfmt.py script
1215            - python-docutils <unknown> (embed)
1216            NOTE: embeds stdlib modules: optparse, textwrap
1217            - python-imaging <unknown> (embed)
1218            NOTE: embeds stdlib modules: doctest
1219            - python-mechanize <unknown> (embed)
1220            NOTE: embeds stdlib modules: doctest
1221            - twill <unknown> (embed)
1222            NOTE: embeds stdlib modules: subprocess
1223            - zeroc-ice <unknown> (embed)
1224            NOTE: embeds stdlib modules: subprocess
1225            - wxwidgets2.8 <unknown> (embed)
1226            NOTE: embeds stdlib modules: subprocess
1227            - cycle <unknown> (embed)
1228            NOTE: embeds msgfmt.py script
1229            - deluge <unknown> (embed)
1230            NOTE: embeds msgfmt.py script
1231            - opendict <unknown> (embed)
1232            NOTE: embeds msgfmt.py script
1233            - openerp-client <unknown> (embed)
1234            NOTE: embeds msgfmt.py script
1235            - rapidsvn <unknown> (embed)
1236            NOTE: embeds msgfmt.py script
1237            - wammu <unknown> (embed)
1238            NOTE: embeds msgfmt.py script
1239            - gaphor <unknown> (embed)
1240            NOTE: embeds msgfmt.py script
1241            - pida <unknown> (embed)
1242            NOTE: embeds msgfmt.py script
1243            - python-formencode <unknown> (embed)
1244            NOTE: embeds msgfmt.py script
1245    
1246    argparse
1247            - twill <unfixed> (embed)
1248            - ipython <unfixed> (embed)
1249    
1250    coherence
1251            - elisa <unfixed> (embed)
1252    
1253    simpletal
1254            - plastex <unfixed> (embed)
1255    
1256    flickrpc (not packaged in Debian, http://burtonini.com/bzr/flickrpc/)
1257            - postr <unfixed> (embed)
1258            - elisa <unfixed> (embed)
1259    
1260    simplegeneric (not packaged in Debian, http://pypi.python.org/pypi/simplegeneric)
1261            - apertium-tolk <unfixed> (embed)
1262            - ipython <unfixed> (embed)
1263            - virtaal <unfixed> (embed)
1264    
1265    distribute
1266            - setuptools <removed> (old-version)
1267    
1268    rails
1269            - jruby1.2 <unfixed> (embed) [./bench/rails/*]
1270            - libgettext-ruby <unfixed> (embed) [./samples/rails/*]
1271            - libopenid-ruby <unfixed> (embed) [./examples/rails_openid/*]
1272            - thin <unfixed> (embed) [./spec/rails_app/*]
1273            NOTE: this is a subdirectory of examples, which in general is a non-issue, but may
1274            NOTE: be dangerous if developers are naively basing their code off of the examples
1275            NOTE: prototype.js is among the example files
1276    
1277    lucene2
1278            - lucene <unfixed> (old-version)
1279            - pylucene <unfixed> (embed)
1280            - libpdfbox-java <unfixed> (embed)
1281            - libfontbox-java <unfixed> (embed)
1282            - libjempbox-java <unfixed> (embed)
1283            - solr <unfixed> (embed)
1284    
1285    unicode-data
1286            - syslinux <unfixed> (embed)
1287            - camomile <unfixed> (embed)
1288            - fribidi <unfixed> (embed)
1289            - m17n-db <unfixed> (embed)
1290            - sbcl <unfixed> (embed)
1291            - heimdal <unfixed> (embed)
1292            - icu <unfixed> (embed)
1293            - icu4j <unfixed> (embed)
1294            - krb5 <unfixed> (embed)
1295            - moodle <unfixed> (embed)
1296            - openldap <unfixed> (embed)
1297            - pike7.6 <unfixed> (embed)
1298            - samba <unfixed> (embed)
1299            - samba4 <unfixed> (embed)
1300            - cmucl <unfixed> (embed)
1301            - typo3-src <unfixed> (embed)
1302            - mauve <unfixed> (embed)
1303            - texlive-bin <unfixed> (embed)
1304            - ypsilon <unfixed> (embed)
1305            - jeuclid <unfixed> (embed)
1306            - charmap.app <unfixed> (embed)
1307            - clisp <unfixed> (embed)
1308            - gnulib <unfixed> (embed)
1309            - opensrs-client <unfixed> (embed)
1310            - saxonb <unfixed> (embed)
1311            - rails <unfixed> (embed)
1312    
1313    feedparser
1314            - rawdog <unfixed> (embed)
1315            - miro <unfixed> (embed)
1316            - calibre <unfixed> (embed)
1317            - freevo <unfixed> (embed)
1318            - pida <unfixed> (embed)
1319            - planet-venus <unfixed> (embed)
1320            - plone3 <unfixed> (embed)
1321            - exaile <unknown> (embed)
1322            - screenlets <unknown> (embed)
1323            NOTE: included twice

Legend:
Removed from v.7923  
changed lines
  Added in v.13215

  ViewVC Help
Powered by ViewVC 1.1.5