CVE-2004-2687 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 88.2% (pctl 100)
Patch early
A public exploit exists.
Description
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 88.2% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-16 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| apple | xcode |
| samba | samba |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | DistCC Daemon - Command Execution (Metasploit) | 2002-02-01 |
References
- http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html
- http://distcc.samba.org/security.html
- http://lists.samba.org/archive/distcc/2004q3/002550.html
- http://lists.samba.org/archive/distcc/2004q3/002562.html
- http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec
- http://www.osvdb.org/13378
- http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html
- http://distcc.samba.org/security.html
- http://lists.samba.org/archive/distcc/2004q3/002550.html
- http://lists.samba.org/archive/distcc/2004q3/002562.html
- http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec
- http://www.osvdb.org/13378
→ the Explorer · watch your stack · NVD