PT-2026-95016 · Midnightbsd · Mport
CVSS v4.0
6.0
Medium
| Vector | AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mport versions prior to 2.7.8
Description
The MidnightBSD Package Manager fails to enforce HTTPS for repository and package mirror URLs within the
mport fetch index(), mport fetch bootstrap index(), and mport fetch bundle() functions located in libmport/fetch.c. This lack of url is https() verification allows a network-positioned attacker to intercept and modify cleartext traffic during package index retrieval or package downloads, potentially compromising the integrity of the downloaded packages or the package selection process.Recommendations
Update to version 2.7.8.
Exploit
Fix
Insufficient Verification of Data Authenticity
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mport