PT-2026-95011 · Mport · Mport
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mport versions prior to 2.7.8
Description
The
mport verify package() function in libmport/verify.c may continue execution after MD5File() or SHA256 File() fails. This allows the system to compare an expected checksum against stale data remaining in the hash buffer instead of a newly computed digest. An attacker who can influence an installed file or the conditions causing the hashing process to fail could hide a checksum failure or obtain a misleading integrity result.Recommendations
Update to version 2.7.8.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mport