Impact
The vulnerability resides in the MidnightBSD package manager, mport. During installation, the function do_actual_install() performed path‑based lstat, chown, stat, and chmod operations on files to set ownership and permissions. A local attacker with write access to a target directory can replace a file that has just been verified with a symlink before the ownership or mode changes are applied. The privileged changes are then redirected through the symlink to an attacker‑chosen path, allowing the attacker to alter the permissions or ownership of arbitrary files on the system. This compromises filesystem integrity and can be used to elevate privileges. The weakness is a time‑of‑check to time‑of‑use race condition and a path traversal flaw (CWE‑367 and CWE‑59).
Affected Systems
The flaw affects installations performed with MidnightBSD mport version 2.7.7 and earlier. The package manager itself is the vulnerable component; any system using the affected mport for package installations is at risk. Version 2.7.8 and later include a fix that removes the race condition by handling ownership and permission changes in a safe order.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. The EPSS score is below 1 %, indicating a low likelihood of exploitation observed so far. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires local write access to the installation target directory and occurs during privileged package installation, so the attack vector is local.
OpenCVE Enrichment