AUR web interface

Tasklist

FS#5403 - AUR allows (Un)Safe Flag for non-privileged users

Attached to Project: AUR web interface
Opened by Thomas Bächler (brain0) - Thursday, 14 September 2006, 10:48 GMT
Task Type Bug Report
Category Backend
Status Closed
Assigned To Douglas Soares de Andrade (dsa)
Architecture All
Severity Critical
Priority Normal
Reported Version 1.2.9
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

I looked over the AUR code for the first time and noticed a security vulnerability which can be witnessed here:
http://aur.archlinux.org/packages.php?do_Details=1&ID=6098
As you can see, this page says "The above files have been verified (by aursecurityvulnerability) and are safe to use.", while "aursecurityvulnerability" is an unprivileged user I created. The problem is in web/html/packages.php at the line

if (!empty($ids) || $atype == "User")

which should probably be one of

if (!empty($ids) && $atype != "User")
if (!(empty($ids) || $atype == "User"))
This task depends upon

Closed by  Simo Leone (neotuli)
Sunday, 17 September 2006, 20:37 GMT
Reason for closing:  Fixed
Additional comments about closing:  if (!empty($ids) && $atype == "Trusted User")

I didn't actually test the fix though... someone might wanna do that.
Comment by Douglas Soares de Andrade (dsa) - Friday, 15 September 2006, 23:27 GMT
Thanks for the report brain0.
I going to look at it.

Loading...