Back

LOW

GConfd uses non-unique directory name in /tmp leading to local DoS

Published Dec 22, 2006

Description

The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome.

Affected products

Remediation

Red Hat statement

The Red Hat Product Security has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 3, 4, or 5.

Metrics

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 22, 2006
Updated Aug 7, 2024
Reserved Dec 22, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date n/a