Impact
mport is the MidnightBSD package manager. Prior to version 2.7.8, the create_sample_file() function in libmport/bundle_read_install_pkg.c failed to constrain absolute source and destination paths from the sample-file manifest directive to the configured installation root. A malicious or malformed package manifest can therefore direct privileged sample-file handling to copy or write files outside the installation root, potentially overwriting critical system files and undermining filesystem integrity. The weakness is a path traversal flaw, identified as CWE‑22.
Affected Systems
All MidnightBSD installations running mport 2.7.7 or earlier are vulnerable. The issue resides in the mport package manager component, affecting any package that includes sample-file manifest entries. Users must be aware that any package installed by an account with installation privileges on those versions is at risk.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, while the EPSS score of less than 1% suggests a very low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits are known. Nevertheless, an adversary who can install or modify a package manifest—requiring privileged access to run mport—could overwrite arbitrary files outside the root directory, potentially facilitating privilege escalation or system compromise. The overall risk remains moderate, but the impact of successful exploitation would be significant.
OpenCVE Enrichment