FS#51514 - [uglify-js] 2.7.4-1 shows permission warning about /usr/lib/nodules/ at install time

Attached to Project: Community Packages
Opened by Ronan (ronjouch) - Monday, 24 October 2016, 02:46 GMT
Last edited by Levente Polyak (anthraxx) - Wednesday, 26 October 2016, 01:07 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Felix Yan (felixonmars)
Architecture All
Severity Critical
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 2
Private No

Details

Description:

When installing the package, pacman shows this error:

warning: directory permissions differ on /usr/lib/node_modules/
filesystem: 755 package: 777

Additional info:
* uglify-js 2.7.4-1
* nodejs-6.9.1-1, npm-3.10.9-1

Steps to reproduce:

* Install uglify-js 2.7.4-1
* I don't remember having manually touched /usr/lib/node_modules/
This task depends upon

Closed by  Levente Polyak (anthraxx)
Wednesday, 26 October 2016, 01:07 GMT
Reason for closing:  Fixed
Additional comments about closing:  uglify-js 2.7.4-2
Comment by Levente Polyak (anthraxx) - Tuesday, 25 October 2016, 23:17 GMT
this is actually a security concern on a multi-user system if /usr/lib/node_modules/ gets created with 777 (when its the first package) allowing possible code execution as other users (including root).
I'm raising the severity

Loading...