PT-2006-7299 · Gnome · Gconf
Lubomir Kundrak
·
Published
2006-12-22
·
Updated
2011-03-08
·
CVE-2006-6698
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
GConf version 2.14.0
Description:
The issue allows local users to cause a denial of service by creating directories ahead of time, preventing other users from using Gnome. This occurs because the GConf daemon creates temporary files under directories with names based on the username.
Recommendations:
For GConf version 2.14.0, consider setting the GCONF GLOBAL LOCKS environment variable to prevent the creation of temporary files under user-based directories as a temporary workaround. Restrict access to the directories where temporary files are created to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gconf