Impact
mport, the MidnightBSD Package Manager, lacked a preflight check for non‑directory assets that existed on disk before version 2.7.8. A malicious or conflicting package could therefore overwrite a file owned by another package or unmanaged by mport, compromising local filesystem integrity and corrupting the package database, which may enable unauthorized manipulation of system files. This behavior represents a CWE‑668 vulnerability, as it permits overwriting files without proper ownership checks, and it also reflects CWE‑73 characteristics, since the package files can reference paths that are not validated, potentially leading to unintended file modification.
Affected Systems
MidnightBSD’s mport package manager, specifically all releases prior to 2.7.8, is affected. The defect resides in libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h within this product.
Risk and Exploitability
The vulnerability scores a CVSS of 6, indicating medium severity, and the EPSS score is less than 1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires local privileged execution of mport and is only possible when the operator does not enable the force flag, so the overall risk remains moderate but unlikely to be observed in the wild.
OpenCVE Enrichment