Midnightbsd
Midnightbsd Mport: vulnerabilidades y CVE
Midnightbsd Mport tiene 13 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses13
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54584 | Media (5.3) | 0.47% | — | 21 sept 2026 | mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a… |
| CVE-2026-54587 | Media (5.8) | 0.10% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission… |
| CVE-2026-54585 | Media (6) | 0.54% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to… |
| CVE-2026-54583 | Alta (8.3) | 0.54% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths.… |
| CVE-2026-54582 | Media (6) | 0.55% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across… |
| CVE-2026-54581 | Alta (8.3) | 0.22% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash… |
| CVE-2026-54586 | Media (6) | 0.15% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs… |
| CVE-2026-54580 | Alta (8.3) | 0.26% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently… |
| CVE-2026-54579 | Baja (2.3) | 0.16% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A… |
| CVE-2026-54578 | Baja (2) | 0.11% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash… |
| CVE-2026-54577 | Baja (2) | 0.16% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an… |
| CVE-2026-54576 | Media (5.8) | 0.10% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A… |
| CVE-2026-54575 | Media (5.8) | 0.12% | — | 17 sept 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.