← Back

CVE-2004-2687

Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.

Affected (2)

Products: Apple: Xcode · Samba: Samba
1 product
Xcode
1 product
Samba
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.5
Up to 2.18.3

Related CWEs

References (12)

Timeline

No history available yet.