CVE-2019-3467: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only
  • Debian Debian-Lan-Config: before 0.26 (fixed in 0.26)
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Skolelinux Debian-Edu-Config: before 2.11.10 (fixed in 2.11.10)

Published 2019-12-23. Last modified 2026-06-17.