Impact
The mport installer functions failed to enforce HTTPS only URLs when fetching package indexes and bundles. As a result, any repository or mirror URL that used cleartext HTTP could be intercepted and altered by a network‑positioned attacker, allowing tampering with package metadata or delivering malicious package binaries. This flaw permits an attacker to compromise package selection or the integrity of installed software on the host.
Affected Systems
The problem exists in MidnightBSD’s package manager, mport, before version 2.7.8. Any system running a pre‑2.7.8 build of mport that uses HTTP or non‑HTTPS URLs for package repositories or mirrors is affected.
Risk and Exploitability
The CVSS base score of 6 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be positioned on the network path between the host and the remote repository or mirror and to supply HTTP URLs for those sources. Once positioned, the attacker can modify the index or package data because the code accepted non‑HTTPS URLs without validation. The attack does not require elevated privileges on the target system, making it relatively straightforward if network control is achieved.
OpenCVE Enrichment