CVE-2024-11681

A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:macports:macports:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

29 Jul 2025, 19:26

Type Values Removed Values Added
First Time Apple macos
Macports
Apple
Macports macports
References () https://github.com/google/security-research/security/advisories/GHSA-2j38-pjh8-wfxw - () https://github.com/google/security-research/security/advisories/GHSA-2j38-pjh8-wfxw - Exploit, Vendor Advisory
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:macports:macports:*:*:*:*:*:*:*:*

07 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 15:15

Updated : 2025-07-29 19:26


NVD link : CVE-2024-11681

Mitre link : CVE-2024-11681


JSON object : View

Products Affected

apple

  • macos

macports

  • macports
CWE

No CWE.