CVE-2004-2687
high · 9.3A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
9.3
CVSS
88.2%
EPSS (exploit prob.)
100th
EPSS percentile
2004-12-31
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-16
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | xcode | 1.5 |
| samba | samba | <= 2.18.3 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html
- http://distcc.samba.org/security.html
- http://lists.samba.org/archive/distcc/2004q3/002550.html
- http://lists.samba.org/archive/distcc/2004q3/002562.html
- http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec
- http://www.osvdb.org/13378
- http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html
- http://distcc.samba.org/security.html
- http://lists.samba.org/archive/distcc/2004q3/002550.html
- http://lists.samba.org/archive/distcc/2004q3/002562.html
- http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec
- http://www.osvdb.org/13378
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-2687