Debian Security Advisory
DLA-2041-1 debian-edu-config -- LTS security update
- Date Reported:
- 18 Dec 2019
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 946797.
In Mitre's CVE dictionary: CVE-2019-3467.
- More information:
It was discovered that debian-edu-config, the package containing the configuration files and scripts for Debian Edu (Skolelinux), contained an insecure configuration for kadmin, the Kerberos administration server. The insecure configuration allowed every user to change other users' passwords, thus impersonating them and possibly gaining their privileges.
The bug was not exposed in the officially documented user management frontends of Debian Edu, but could be abused by local network users knowing how to use the Kerberos backend.
For Debian 8
Jessie, this problem has been fixed in version 1.818+deb8u3.
We recommend that you upgrade your debian-edu-config packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS