brother-mfcj435w-cups-bin

maintainer Quantum_C · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt i386 Debian binary (.deb containing a CUPS wrapper, i.e. executed code) directly from brother.com/pub/bsc/linux/packages/ over plain HTTP (no TLS). While brother.com is the legitimate vendor domain, the use of unencrypted HTTP means the binary could be intercepted and replaced in transit (MITM). The md5sums check provides weak integrity protection (MD5 is cryptographically broken and trivially collided). The package() function extracts and installs the binary directly without any source build, so whatever is in the .deb lands on the system. The combination of: (1) executed prebuilt binary, (2) plain HTTP transport, and (3) only MD5 integrity check constitutes a real, if modest, supply-chain/code-execution concern. The host is the official Brother domain so this is not a personal/unofficial host, which lowers the risk somewhat, but the HTTP+MD5 combination for an executed binary keeps this at MEDIUM rather than clean/low.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("http://www.brother.com/pub/bsc/linux/packages/mfcj435wcupswrapper-3.0.0-1.i386.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt i386 Debian binary (.deb containing a CUPS wrapper, i.e. executed code) directly from brother.com/pub/bsc/linux/packages/ over plain HTTP (no TLS). While brother.com is the legitimate vendor domain, the use of unencrypted HTTP means the binary could be intercepted and replaced in transit (MITM). The md5sums check provides weak integrity protection (MD5 is cryptographically broken and trivially collided). The package() function extracts and installs the binary directly without any source build, so whatever is in the .deb lands on the system. The combination of: (1) executed prebuilt binary, (2) plain HTTP transport, and (3) only MD5 integrity check constitutes a real, if modest, supply-chain/code-execution concern. The host is the official Brother domain so this is not a personal/unofficial host, which lowers the risk somewhat, but the HTTP+MD5 combination for an executed binary keeps this at MEDIUM rather than clean/low.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Mitchell Sinclair <quantum_c@hotmail.comm>
2pkgname=brother-mfcj435w-cups-bin
3pkgver=3.0.0
4pkgrel=1
5pkgdesc="CUPS wrapper for Brother MFC-J435W printer"
6arch=("i686" "x86_64")
7url="https://support.brother.com/g/b/producttop.aspx?c=ca&lang=en&prod=mfcj435w_us"
8license=("EULA")
9groups=("base-devel")
10source=("http://www.brother.com/pub/bsc/linux/packages/mfcj435wcupswrapper-3.0.0-1.i386.deb")
11md5sums=("8756f5964a9f9f811cc1b855f7593c2f")
12package() {
13 tar -xf data.tar.gz -C "${pkgdir}"
14}
15

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion