Vulnerability Details CVE-2019-3467
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2019-3467
-
cpe:2.3:a:debian:debian-lan-config:-
-
cpe:2.3:a:debian:debian-lan-config:0.19
-
cpe:2.3:a:debian:debian-lan-config:0.23
-
cpe:2.3:a:debian:debian-lan-config:0.25
-
cpe:2.3:a:skolelinux:debian-edu-config:-
-
cpe:2.3:a:skolelinux:debian-edu-config:1.818
-
cpe:2.3:a:skolelinux:debian-edu-config:1.929
-
cpe:2.3:a:skolelinux:debian-edu-config:2.10.65
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0