|
|
Subscribe / Log in / New account

Debian alert DLA-2041-1 (debian-edu-config)

From:  Dominik George <natureshadow@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2041-1] debian-edu-config security update
Date:  Wed, 18 Dec 2019 14:55:34 +0100
Message-ID:  <20191218135534.ikc3ycmp77opjdro@portux.naturalnet.de>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : debian-edu-config Version : 1.818+deb8u3 CVE ID : CVE-2019-3467 Debian Bug : 946797 It was discovered that debian-edu-config, the package containing the configuration files and scripts for Debian Edu (Skolelinux), contained an insecure configuration for kadmin, the Kerberos administration server. The insecure configuration allowed every user to change other users' passwords, thus impersonating them and possibly gaining their privileges. The bug was not exposed in the officially documented user management frontends of Debian Edu, but could be abused by local network users knowing how to use the Kerberos backend. For Debian 8 "Jessie", this problem has been fixed in version 1.818+deb8u3. We recommend that you upgrade your debian-edu-config packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQJlBAEBCgBPFiEEPJ1UpHV1wCb7F/0mt5o8FqDE8pYFAl36L9UxGmh0dHBzOi8v d3d3LmRvbWluaWstZ2VvcmdlLmRlL2dwZy1wb2xpY3kudHh0LmFzYwAKCRC3mjwW oMTylvO7EACGHllByHzJBGpQP+Ae0CCT5uDzRIe75upPeFweYJOzx0KjXSGUCyl3 Szp9/FKhZDViQsL8jyc9cdyMzNUpas03I9sPflHi/sWDIUQVd77ANXnBDK7+pQxh 70QiUfA5rjKc2I7gD4GJiNZGenOf3QwzI6LU3KAxeRjh952NF0GbSigiiESGGkdk YtLQUEc9j9sJbP2oUC4nr9FpQkRU0K02ZrpQ9vS69jr2tyb2q6qsUDq/ksObf/B/ IAsqlNyHbvivh1meHsHB8Akxroxr9vWOYRQXVm9OqUUEh9+J1VXyEF338f68TG6s /2USZbEevydT6fjTUXbM1uLIp+KSKn7QKVA6twi4fuuIEMgtC1z2FwqOQu+6+oxC +z60RBSoWrS6SV2alm8/iTyb2CbBncqyosBjjF8tUUzlfhl6PNz7VMzCIV5J/ll5 Pz1nHL+Z/ICoWkDY3OyaJJ4/HD0l30396HY1fPy1ZLs7OQEOZ+vx+LaLvWubVwPJ roX1sqoybh1qN0fWe6u+9MqgUoYYINBbKFuzXhwF8oHa+IZjfO0+TEBVXtArYHW6 HNbbjfB7VUYj0xp5JYYTdIrlU1zTZI+7FD1vCI3AtZT2yOD96X3Sulh4HFFdh31g em1FlehdiK2Rv9mKC1YPmbVdYE13aeR1qV+B32jt/6S+eznXszuj/Q== =9EvY -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds