Impact
The vulnerability lies in the mport package manager's ping implementation, which accepts ICMP replies without checking the icmp_id or icmp_seq fields and uses a hard‑coded IP-header offset instead of reading the actual header length. An attacker capable of injecting or spoofing ICMP replies can manipulate mirror latency selection to favor malicious mirrors, and a crafted packet containing IP options can shift the header alignment, causing an out‑of‑bounds read and the possibility of leaking memory contents. The weakness corresponds to CWE‑125 and CWE‑345.
Affected Systems
MidnightBSD mport package manager versions older than 2.7.8. These versions are affected by the unchecked ICMP reply handling described above.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score of <1 % suggests the likelihood of exploitation is very low. The vulnerability is not present in CISA’s KEV catalog, further reducing the risk profile. Exploitation requires a network attacker able to send spoofed or malicious ICMP echo replies that reach the mport process; no privilege escalation, remote code execution, or direct denial‑of‑service tools are required. The impact is limited to potential information disclosure through an out‑of‑bounds read and a degraded ability to select the optimal package mirror.
OpenCVE Enrichment