CVE-2019-3467

unknown
Published — · Modified —
CVSS v3
CVSS v2
VIR risk

Description

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-3467

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2019-3467 NameCVE-2019-3467 DescriptionDebian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE…

CVE-2019-3467

NameCVE-2019-3467
DescriptionDebian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2041-1, DLA-2063-1, DSA-4589-1, DSA-4595-1
Debian Bugs946797, 947459

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
debian-edu-config (PTS)bullseye2.11.56+deb11u4fixed
bullseye (security)2.11.56+deb11u3fixed
bookworm2.12.46~deb12u1fixed
trixie2.12.903~deb13u1fixed
forky, sid2.13.0fixed
debian-lan-config (PTS)bullseye0.28fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
debian-edu-configsourcejessie1.818+deb8u3DLA-2041-1
debian-edu-configsourcestretch1.929+deb9u4DSA-4589-1
debian-edu-configsourcebuster2.10.65+deb10u3DSA-4589-1
debian-edu-configsource(unstable)2.11.10946797
debian-lan-configsourcejessie0.19+deb8u2DLA-2063-1
debian-lan-configsourcestretch0.23+deb9u1DSA-4595-1
debian-lan-configsourcebuster0.25+deb10u1DSA-4595-1
debian-lan-configsource(unstable)0.26947459

Notes

debian-lan-config is effectively the same issue as in debian-edu-config and a somewhat
derived codebase, so same CVE ID is used

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
debian-lan-config is effectively the same issue as in debian-edu-config and a somewhatderived codebase, so same CVE ID is used

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.11.10
debian debianbullseyefixed2.11.10
debian debianforkyfixed2.11.10
debian debiansidfixed2.11.10
debian debiantrixiefixed2.11.10

References

Verify integrity in audit chain (admin only). AS-IS.