VDB
CVE-2004-2687
CVE-2004-2687
PUBLISHED
CVSS 9.300000190734863 CRITICAL
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
EPSS 88.20% · 99.8th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
88.20%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | xcode | 1.5 |
| samba | samba | 0 |
| n/a | n/a | n/a |
Timeline
- Dec 31, 2004 CVE Published
- May 22, 2012 PoC Published
- Jan 6, 2013 PoC Published
- Oct 14, 2013 PoC Published
- Jan 1, 2014 PoC Published
- Jan 5, 2014 PoC Published
- Jan 17, 2014 PoC Published
- May 27, 2014 PoC Published
- Aug 12, 2014 PoC Published
- Jan 17, 2015 PoC Published
- Jan 28, 2015 PoC Published
- Feb 9, 2015 PoC Published
References
- http://distcc.samba.org/security.html url
- 20050310 XCode 1.5 and distcc 2.x Exploit mailing-list
- http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec url
- [distcc] 20040826 Exploit in distcc ( got compromised ;( ) mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2004-2687 advisory
- http://lists.samba.org/archive/distcc/2004q3/002562.html url
- http://www.osvdb.org/13378 technical