peter bassill · operator
$ cve CVE-2004-2687 JSON

CVE-2004-2687 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 88.2% (pctl 100)

Patch early

A public exploit exists.

Description

distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS88.2% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (2)

VendorProduct
applexcode
sambasamba

Public exploits

SourceTitleDate
exploit-dbDistCC Daemon - Command Execution (Metasploit)2002-02-01

References

→ the Explorer  ·  watch your stack  ·  NVD