foobar2000-component-uie-esplaylist-bin

maintainer defusq · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt DLL (foo_uie_esplaylist.dll) from foo2k.chottu.net, which is a personal/unofficial host rather than an official vendor mirror or well-known ecosystem registry. The DLL is installed into the foobar2000 components directory where it will be loaded and executed by foobar2000. While the MD5 checksum provides minimal integrity verification (MD5 is weak and the host itself could serve a different file), the core concern is that a prebuilt binary from a personal host with no verifiable upstream source represents a genuine supply-chain risk: if the host is compromised or the maintainer is malicious, arbitrary code executes in the context of foobar2000. This is a textbook medium-severity case — an executed binary from an unofficial/personal host.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=('http://foo2k.chottu.net/foo_uie_esplaylist.zip')
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt DLL (foo_uie_esplaylist.dll) from foo2k.chottu.net, which is a personal/unofficial host rather than an official vendor mirror or well-known ecosystem registry. The DLL is installed into the foobar2000 components directory where it will be loaded and executed by foobar2000. While the MD5 checksum provides minimal integrity verification (MD5 is weak and the host itself could serve a different file), the core concern is that a prebuilt binary from a personal host with no verifiable upstream source represents a genuine supply-chain risk: if the host is compromised or the maintainer is malicious, arbitrary code executes in the context of foobar2000. This is a textbook medium-severity case — an executed binary from an unofficial/personal host.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Connor McFarlane <cm at semtex dot net>
2
3pkgname=foobar2000-component-uie-esplaylist-bin
4pkgver=0.1.3.9
5pkgrel=4
6_fooname='foo_uie_esplaylist'
7pkgdesc='A playlist component for foobar2000 (column & default UI)'
8arch=('any')
9url='http://foo2k.chottu.net/#esp'
10license=('cc-by-3.0')
11depends=('foobar2000>=1.0.0')
12source=('http://foo2k.chottu.net/foo_uie_esplaylist.zip')
13md5sums=('1b9ce59f12bff9e922f39337c44af77c')
14
15package() {
16 install -Dm644 -t "$pkgdir/usr/share/foobar2000/components/${_fooname}" "$srcdir/${_fooname}.dll"
17}
18
19

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion