Wolfgang Schweer discovered that Debian-LAN did not properly handle ACLs for the Kerberos admin server. A local attacker could possibly use this issue to change the passwords of other users, leading to root privilege escalation. (CVE-2019-3467)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.23+deb9u1build0.18.04.1", "binary_name": "debian-lan-config" } ] }