Impact
The vulnerability stems from missing validation of bundle filenames in mport's fetch component. Malicious package index entries can specify empty, dot, dot‑dot, or slash‑containing filenames, which are then used to construct download and write paths without proper sanitization. As a result, an attacker can cause the package manager to write files outside the intended cache directory or to overwrite arbitrary files, leading to privilege escalation or system compromise.
Affected Systems
This flaw affects all MidnightBSD system installations running mport before version 2.7.8. The vulnerable code resides in libmport/fetch.c and is relevant to all package downloads handled by mport. Vendors and users should check the installed mport version and ensure it is at least 2.7.8.
Risk and Exploitability
The CVSS score is 8.3, indicating a high severity. The EPSS score is below 1%, suggesting that the probability of exploitation is low, and it does not appear in CISA's KEV catalog. The likely attack vector is a compromised or malicious package repository; an attacker who can inject entries into a repository that a user’s mport will consume can exploit the flaw. If exploited, the attacker could write files with arbitrary names outside the intended cache directory, potentially overwriting system files or placing malicious payloads, thereby enabling privilege escalation or persistence. As no public exploit is known, the threat remains theoretical but should be mitigated promptly.
OpenCVE Enrichment