CVE-2004-2687
EPSS 81.0%
Description
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
How to fix CVE-2004-2687
To remediate CVE-2004-2687, upgrade the affected package to a fixed version below.
- Debian/distcc—upgrade to 2.18.1-1 or later
Is CVE-2004-2687 being exploited?
Likely — EPSS is 81.0%, placing CVE-2004-2687 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 2.18.1-1