Executive brief
mport is the package manager for MidnightBSD, a FreeBSD-derived operating system. A flaw in how it processes package manifests could allow a malicious or malformed package to write files outside the intended installation directory, potentially compromising system integrity and enabling unauthorized file modification or system takeover when packages are installed with elevated privileges.
Technical details
A path traversal vulnerability exists in the create_sample_file() function in libmport/bundle_read_install_pkg.c prior to version 2.7.8. The function fails to properly constrain absolute source and destination paths specified in the sample-file manifest directive to the configured mport installation root, allowing an attacker-controlled package manifest to direct file operations outside the intended root directory. An attacker can craft a malicious package containing sample-file directives with absolute paths that, when processed by privileged mport operations, write arbitrary files to the filesystem. The vulnerability requires a user to install or process a malicious package, but would be exploited with package manager privileges. The issue is fixed in version 2.7.8.
Affected products
- MidnightBSD mport prior to 2.7.8
Timeline
- 2026-09-17: disclosed
- 2026-05-14: patched: Fixed in version 2.7.8