CVE-2019-3467

NameCVE-2019-3467
DescriptionDebian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2041-1, DLA-2063-1, DSA-4589-1, DSA-4595-1
Debian Bugs946797, 947459

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
debian-edu-config (PTS)buster, buster (security)2.10.65+deb10u8fixed
bullseye2.11.56+deb11u4fixed
bullseye (security)2.11.56+deb11u3fixed
bookworm2.12.44~deb12u1fixed
sid, trixie2.12.44fixed
debian-lan-config (PTS)buster, buster (security)0.25+deb10u1fixed
bullseye0.28fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
debian-edu-configsourcejessie1.818+deb8u3DLA-2041-1
debian-edu-configsourcestretch1.929+deb9u4DSA-4589-1
debian-edu-configsourcebuster2.10.65+deb10u3DSA-4589-1
debian-edu-configsource(unstable)2.11.10946797
debian-lan-configsourcejessie0.19+deb8u2DLA-2063-1
debian-lan-configsourcestretch0.23+deb9u1DSA-4595-1
debian-lan-configsourcebuster0.25+deb10u1DSA-4595-1
debian-lan-configsource(unstable)0.26947459

Notes

debian-lan-config is effectively the same issue as in debian-edu-config and a somewhat
derived codebase, so same CVE ID is used

Search for package or bug name: Reporting problems