In TCP mode, distcc checks the client IP address against a whitelist, which (iirc) is required but can be set quite loosely. There is of course no guarantee that every user on a permitted client address is friendly. Once the connection is established the client can reasonably easily manipulate the server into running arbitrary commands. Upstream issue: https://github.com/distcc/distcc/issues/155
Created distcc tracking bugs for this issue: Affects: epel-all [bug 1660408] Affects: fedora-all [bug 1660407]
IBM will do testing as Red Hat will not have access to the new hardware for testing. Setting to OtherQA.
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.