distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html - | |
References | () http://distcc.samba.org/security.html - | |
References | () http://lists.samba.org/archive/distcc/2004q3/002550.html - | |
References | () http://lists.samba.org/archive/distcc/2004q3/002562.html - | |
References | () http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec - Exploit | |
References | () http://www.osvdb.org/13378 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:53
NVD link : CVE-2004-2687
Mitre link : CVE-2004-2687
CVE.ORG link : CVE-2004-2687
JSON object : View
Products Affected
samba
- samba
apple
- xcode
CWE
CWE-16
Configuration