First published: Fri Dec 22 2006(Updated: )
The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Gconf | =2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6698 has a moderate severity level as it allows local users to cause a denial of service.
CVE-2006-6698 affects GConf 2.14.0 by allowing local users to create temporary directories, blocking access for other users.
Local users on systems running GConf 2.14.0 are affected by CVE-2006-6698.
No, CVE-2006-6698 cannot be exploited remotely as it requires local user access.
A possible workaround for CVE-2006-6698 is to ensure that the GCONF_GLOBAL_LOCKS is set to prevent local users from creating the necessary directories.