CVE-2019-3467
published 2019-12-23CVE-2019-3467: Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.50%
40.2th percentile
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian-edu-config | < debian-edu-config 2.11.10 (bookworm) | debian-edu-config 2.11.10 (bookworm) |
| debian | debian-lan-config | < 0.26 | 0.26 |
| debian | debian-lan-config | < debian-edu-config 2.11.10 (bookworm) | debian-edu-config 2.11.10 (bookworm) |
| debian | debian-lan-config | >= 0 < 0.26 | 0.26 |
| debian | debian-lan-config | >= 0 < 0.23+deb9u1build0.18.04.1 | 0.23+deb9u1build0.18.04.1 |
| debian | debian_edu | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| skolelinux | debian-edu-config | < 2.11.10 | 2.11.10 |
| skolelinux | debian-edu-config | >= 0 < 2.11.10 | 2.11.10 |
| skolelinux | debian-edu-config | >= 0 < 2.11.10 | 2.11.10 |
| skolelinux | debian-edu-config | >= 0 < 2.11.10 | 2.11.10 |
| skolelinux | debian-edu-config | >= 0 < 2.11.10 | 2.11.10 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwf4-gh23-f5jj: Debian-edu-config all versions < 2
ghsa_unreviewed·2022-05-24
CVE-2019-3467 [HIGH] CWE-732 GHSA-qwf4-gh23-f5jj: Debian-edu-config all versions < 2
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
OSV
debian-lan-config vulnerabilities
osv·2020-09-22·CVSS 7.8
CVE-2019-3467 [HIGH] debian-lan-config vulnerabilities
debian-lan-config vulnerabilities
Wolfgang Schweer discovered that Debian-LAN did not properly handle ACLs
for the Kerberos admin server. A local attacker could possibly use this
issue to change the passwords of other users, leading to root privilege
escalation. (CVE-2019-3467)
OSV
CVE-2019-3467: Debian-edu-config all versions < 2
osv·2019-12-23·CVSS 7.8
CVE-2019-3467 [HIGH] CVE-2019-3467: Debian-edu-config all versions < 2
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
Ubuntu
Debian-LAN vulnerabilities
vendor_ubuntu·2020-09-22·CVSS 7.8
CVE-2019-3467 [HIGH] Debian-LAN vulnerabilities
Title: Debian-LAN vulnerabilities
Summary: Debian-LAN could be made to change Kerberos user passwords or run programs
as an administrator.
Wolfgang Schweer discovered that Debian-LAN did not properly handle ACLs
for the Kerberos admin server. A local attacker could possibly use this
issue to change the passwords of other users, leading to root privilege
escalation. (CVE-2019-3467)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-3467: debian-edu-config - Debian-edu-config all versions < 2.11.10, a set of configuration files used for ...
vendor_debian·2019·CVSS 7.8
CVE-2019-3467 [HIGH] CVE-2019-3467: debian-edu-config - Debian-edu-config all versions < 2.11.10, a set of configuration files used for ...
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
Scope: local
bookworm: resolved (fixed in 2.11.10)
bullseye: resolved (fixed in 2.11.10)
forky: resolved (fixed in 2.11.10)
sid: resolved (fixed in 2.11.10)
trixie: resolved (fixed in 2.11.10)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=946797https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=947459https://lists.debian.org/debian-lts-announce/2019/12/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00012.htmlhttps://seclists.org/bugtraq/2019/Dec/34https://seclists.org/bugtraq/2019/Dec/44https://security-tracker.debian.org/tracker/CVE-2019-3467https://usn.ubuntu.com/4530-1/https://www.debian.org/security/2019/dsa-4589https://www.debian.org/security/2019/dsa-4595https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=946797https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=947459https://lists.debian.org/debian-lts-announce/2019/12/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00012.htmlhttps://seclists.org/bugtraq/2019/Dec/34https://seclists.org/bugtraq/2019/Dec/44https://security-tracker.debian.org/tracker/CVE-2019-3467https://usn.ubuntu.com/4530-1/https://www.debian.org/security/2019/dsa-4589https://www.debian.org/security/2019/dsa-4595
2019-12-23
Published