Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2019-12-23T18:04:11

Updated: 2024-08-04T19:12:09.531Z

Reserved: 2018-12-31T00:00:00

Link: CVE-2019-3467

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-12-23T19:15:11.823

Modified: 2022-12-22T20:20:16.733

Link: CVE-2019-3467

cve-icon Redhat

No data.