Loading
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.
Use CWE-16, Apple vendor hub and Xcode product page to widen CVE-2004-2687 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-48384, CVE-2025-43505 and CVE-2025-43371 for nearby disclosures in the same product family.