CVE-2024-11681 describes a critical vulnerability in MacPorts where a malicious or compromised mirror can execute arbitrary commands as root on a client machine running 'port selfupdate'. This medium-severity vulnerability (CVSS 6.8) has a network attack vector and high impact on integrity, allowing an attacker to gain root privileges. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for root-level compromise necessitates prompt attention for affected Apple macOS and MacPorts users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.5CPE matchmatch criteria | cpe:2.3:a:macports:macports:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.