You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa debian-lan-config

Sigurnosni nedostatak programskog paketa debian-lan-config

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4530-1
September 22, 2020

debian-lan-config vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS

Summary:

Debian-LAN could be made to change Kerberos user passwords or run programs
as an administrator.

Software Description:
– debian-lan-config: FAI config space for the Debian-LAN system

Details:

Wolfgang Schweer discovered that Debian-LAN did not properly handle ACLs
for the Kerberos admin server. A local attacker could possibly use this
issue to change the passwords of other users, leading to root privilege
escalation. (CVE-2019-3467)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
debian-lan-config 0.23+deb9u1build0.18.04.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4530-1
CVE-2019-3467

Package Information:
https://launchpad.net/ubuntu/+source/debian-lan-config/0.23+deb9u1build0.18.04.1

—–BEGIN PGP SIGNATURE—–

iQEzBAEBCAAdFiEElnO/d49FoUPK9fwytGdj0GOh2+wFAl9qPQEACgkQtGdj0GOh
2+ylZAgAhLu0G+4PBFtP30GGbBTwwvEMNXXqj/dJwzMxdDqCu4g2YfuqjyncE++K
RxoCRrPIoSes8+wjXya3JodUgeNDTTKKOUZQgyZbb3wQelyZG2I7+4QfWA0g6zn1
3EfD65La2Zoj/tmi/kj8bXFHBKxcfYySu99KCN7/Zv4y+FcRFHKm4rbO0V2KvTXi
BNT9itt2C5kKi69H5wq/boP+zH9R91bgppegCpOXJhltcWbZVgMlyHUHVyBZaoge
cSIVRxlqg/BWxTzZAsInFj8kgp9LdCp57ow13Dz4W9nlslDqJgbsYWO7SjDIZjS6
LyEs87ggmnfipHlc8DYxEUhMfsiTOA==
=StKY
—–END PGP SIGNATURE—–

AutorToni Vugdelija
Cert idNCERT-REF-2020-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programske biblioteke libqt4

Otkriveni su sigurnosni nedostaci programske biblioteke libqt4 za operacijski sustav openSUSE. Otkriveni nedostaci potencijalnim udaljenim napadačima omogućuju izazivanje DoS stanja...

Close