CVE-2024-11681 Details
Description
A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.
A vulnerability exists in the MacPorts package manager for macOS, specifically in the PortsCLI component. When a user runs 'port selfupdate' against a malicious or compromised MacPorts mirror, the mirror can execute arbitrary commands as root on the user's machine. This issue arises because the MacPorts client uses 'rsync' to download update files from the mirror. If the mirror serves a valid, signed archive along with additional crafted files, the client can be tricked into executing commands specified in those files, bypassing signature validation.
Users are advised to update MacPorts to the latest version, where this vulnerability has been addressed. Instructions for updating MacPorts can be found on the MacPorts website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/google/security-research/security/advisories/GHSA-2j38-pjh8-wfxw | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| macports macports | < 2.10.5 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | Initial Analysis | [email protected] |
| Jan 7, 2025 | CVE Modified | CISA-ADP |
| Jan 7, 2025 | New CVE Received | [email protected] |