Impact
The mport_fetch_bootstrap_index() function in MidnightBSD’s mport package manager allowed the command to return success even when hash verification of the bootstrap index failed. This flaw enabled an attacker capable of altering the bootstrap index or its transport path to provide an unverified or tampered index, thereby allowing the installation of malicious packages during system bootstrapping. The vulnerability can thus lead to a compromise of the integrity of the entire system if malicious code is injected through the bootstrap process.
Affected Systems
The vulnerability affects MidnightBSD mport versions prior to 2.7.8. It is resolved in release 2.7.8. Only the MidnightBSD package manager is impacted; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the short term, and the issue is not currently listed in the CISA KEV catalog. The likely attack vector is a network attacker or a compromised mirror that can modify or substitute the bootstrap index. Successful exploitation would require the attacker to supply altered index data that bypasses hash checks, after which mport would continue the bootstrap installation process with that corrupted data, potentially installing compromised packages.
OpenCVE Enrichment