Impact
The mport package manager contains a TOCTOU race condition in privileged fetch and cache‑clean operations. When a local attacker has write access to the package cache or staging path, they can exploit the race between path checks and replacement to redirect downloads or cleanup actions outside the intended cache directory. Additionally, the helper modules invoke subshells using shell‑form syntax, creating a command‐line interpretation risk during privileged execution. Combined, these flaws enable a local attacker to execute arbitrary commands with elevated privileges, potentially compromising the entire system.
Affected Systems
The vulnerability exists in MidnightBSD's mport package manager versions prior to 2.7.8. The affected code resides in libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. Updating to mport 2.7.8 or later removes the race condition and shell‑form invocation issues.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker must be local and possess write permissions to the cache or staging directories to trigger the race, after which they can gain elevated privileges. Due to the required local foothold and the presence of a patch, the overall risk is moderate but actionable.
OpenCVE Enrichment