dambe

maintainer malacology · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt MSI installer from dambe.bio.uottawa.ca (a University of Ottawa bioinformatics lab hosting their own software — not a personal/random host, but still not a standard distribution mirror). Two real concerns: (1) The checksum is 'SKIP', meaning any replacement of the MSI at the source URL would go undetected. (2) The package() function runs 'wine msiexec /i' during the build/install phase, which executes the MSI installer directly — this is code execution of a downloaded binary with no integrity verification. The host appears to be the legitimate upstream vendor (the official DAMBE software page), which reduces but does not eliminate the risk. The combination of no checksum and direct execution of a downloaded binary installer constitutes a genuine supply-chain concern: if the file is ever replaced or the server is compromised, arbitrary code runs on the user's system. This is a real medium-severity issue, not a false positive.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:16 source=("http://dambe.bio.uottawa.ca/software_download/DAMBEX.msi")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt MSI installer from dambe.bio.uottawa.ca (a University of Ottawa bioinformatics lab hosting their own software — not a personal/random host, but still not a standard distribution mirror). Two real concerns: (1) The checksum is 'SKIP', meaning any replacement of the MSI at the source URL would go undetected. (2) The package() function runs 'wine msiexec /i' during the build/install phase, which executes the MSI installer directly — this is code execution of a downloaded binary with no integrity verification. The host appears to be the legitimate upstream vendor (the official DAMBE software page), which reduces but does not eliminate the risk. The combination of no checksum and direct execution of a downloaded binary installer constitutes a genuine supply-chain concern: if the file is ever replaced or the server is compromised, arbitrary code runs on the user's system. This is a real medium-severity issue, not a false positive.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: malacology
2# Contributor: malacology
3
4pkgname=dambe
5pkgver=7
6pkgrel=1
7pkgdesc="New and improved tools for data analysis in molecular biology and evolution"
8arch=('any')
9url="http://dambe.bio.uottawa.ca/DAMBE/dambe.aspx"
10license=('custom')
11depends=(
12 'wine'
13 'wine_gecko'
14 'wine-mono'
15)
16source=("http://dambe.bio.uottawa.ca/software_download/DAMBEX.msi")
17md5sums=('SKIP')
18
19package() {
20 install -dm755 "$pkgdir"/usr/share/applications
21 wine msiexec /i "$srcdir"/DAMBEX.msi
22}
23

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion