GConf Temporary Directory Creation Denial of Service Vulnerability
BID:21762
Info
GConf Temporary Directory Creation Denial of Service Vulnerability
| Bugtraq ID: | 21762 |
| Class: | Design Error |
| CVE: |
CVE-2006-6698 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 26 2006 12:00AM |
| Updated: | Jan 04 2007 06:21PM |
| Credit: | Michael Meeks is credited with the discovery of this vulnerability. |
| Vulnerable: |
GNOME gconf 2.8 GNOME gconf 2.7 |
| Not Vulnerable: | |
Discussion
GConf Temporary Directory Creation Denial of Service Vulnerability
GConf is prone to a local denial-of-service vulnerability due to a design error.
Exploiting this issue allows local attackers to stop GConf from being used by legitimate users.
Versions 2.7 and 2.8 are vulnerable; other versions may also be affected.
GConf is prone to a local denial-of-service vulnerability due to a design error.
Exploiting this issue allows local attackers to stop GConf from being used by legitimate users.
Versions 2.7 and 2.8 are vulnerable; other versions may also be affected.
Exploit / POC
GConf Temporary Directory Creation Denial of Service Vulnerability
An attacker can exploit this issue by creating a directory in '/tmp' with the name 'gconf-$LOGNAME', where $LOGNAME is the username of a target user.
An attacker can exploit this issue by creating a directory in '/tmp' with the name 'gconf-$LOGNAME', where $LOGNAME is the username of a target user.
Solution / Fix
GConf Temporary Directory Creation Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
GConf Temporary Directory Creation Denial of Service Vulnerability
References:
References:
- Bug 141138 �?? gconf can't cope with UID change ... (Michael Meeks)
- Bug 167030 �?? /tmp not cleaned up, which causes bad results if user's UID changes (olaf cbk poznan pl)
- Bugzilla Bug 219279: CVE-2006-6698 GConfd uses non-unique directory name in /tmp (redhat)
- GConf Homepage (GNOME)