PT-2026-95014 · Midnightbsd · Mport
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mport versions prior to 2.7.8
Description
The MidnightBSD Package Manager fails to perform a preflight check for non-directory assets that already exist on the disk during package installation. The logic within
libmport/check preconditions.c, libmport/install primative.c, and libmport/mport private.h does not apply MPORT PRECHECK FILE CONFLICTS. Consequently, a crafted or conflicting package can overwrite files owned by other packages or files not managed by the system. This occurs during privileged installations unless the mport->force variable is explicitly enabled, potentially compromising local filesystem integrity and package database consistency.Recommendations
Update to version 2.7.8.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mport