CVE-2024-42381 describes a critical vulnerability in Homebrew brew versions prior to 4.2.20, specifically within the os/linux/elf.rb component. This flaw allows attackers to achieve code execution by crafting malicious ELF files with custom .interp sections, which are then processed by ldd during an un-sandboxed binary relocation phase. The vulnerability carries a CVSS score of 8.3 (HIGH), indicating a severe risk. It has a network attack vector, high attack complexity, and requires user interaction (UI:R), but can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). The exploit occurs before the user expects package content execution, making it particularly insidious. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are also absent, suggesting low current awareness despite the high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.