9.3

CVE-2004-2687

Exploit
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ XCode Version 1.5
Samba ≫ Samba Version <= 2.18.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 88.2% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2005-03/0183.html
http://distcc.samba.org/security.html
http://lists.samba.org/archive/distcc/2004q3/002550.html
http://lists.samba.org/archive/distcc/2004q3/002562.html
http://www.metasploit.org/projects/Framework/exploits.html#distcc_exec
Exploit
http://www.osvdb.org/13378