CVE-2006-6698
Summary
| CVE | CVE-2006-6698 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-22 18:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome. |
Risk And Classification
Primary CVSS: v2.0 1.9 from [email protected]
AV:L/AC:M/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:L/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 167030 – /tmp not cleaned up, which causes bad results if user's UID changes | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.gnome.org | Exploit |
| GConf Temporary Directory Creation Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 219279 – CVE-2006-6698 GConfd uses non-unique directory name in /tmp leading to local DoS | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit |
| GConf Temporary Directory Local Denial of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-05-29 | Mark J Cox | The Red Hat Security Response Team has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 3, 4, or 5. |
There are currently no legacy QID mappings associated with this CVE.