CVE-2006-6698 Information

Description

The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username even when GCONF_GLOBAL_LOCKS is not set which allows local users to cause a denial of service by creating the directories ahead of time which prevents other users from using Gnome.

Reference

http://bugzilla.gnome.org/show_bug.cgi?id=167030 http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=219279 http://secunia.com/advisories/23452 http://www.securityfocus.com/bid/21762 http://www.vupen.com/english/advisories/2006/5148

Share on: