CVE-2006-6698
Status: ModifiedLow (1.9)—
The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome.
CVSS
- Version: 2.0
- Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P
- Base score: 1.9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.43%
- Percentile among all scored CVEs: 36
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://bugzilla.gnome.org/show_bug.cgi?id=167030
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=219279
- http://secunia.com/advisories/23452
- http://www.securityfocus.com/bid/21762
- http://www.vupen.com/english/advisories/2006/5148
- http://bugzilla.gnome.org/show_bug.cgi?id=167030
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=219279
- http://secunia.com/advisories/23452
- http://www.securityfocus.com/bid/21762
- http://www.vupen.com/english/advisories/2006/5148
Raw JSON (NVD)
Show
{
"id": "CVE-2006-6698",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 1.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-12-22T18:28:00.000",
"references": [
{
"url": "http://bugzilla.gnome.org/show_bug.cgi?id=167030",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=219279",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23452",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/21762",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/5148",
"source": "cve@mitre.org"
},
{
"url": "http://bugzilla.gnome.org/show_bug.cgi?id=167030",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=219279",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/23452",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21762",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/5148",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time, which prevents other users from using Gnome."
},
{
"lang": "es",
"value": "El demonio GConf (gconfd) en GConf 2.14.0 crea archivos temporales bajo directorio con nombres basados en el nombre de usuario, incluso cuando GCONF_GLOBAL_LOCKS no está activo, lo cual permite a usuarios locales provocar denegación de servicio a través de la creación de directorios antes de tiempo, lo cual evita que otros usuarios usen gnome."
}
],
"lastModified": "2026-06-16T22:33:37.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnome:gconf:2.14.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3D8548A-E41C-47A4-A67B-9DDDAEB71555"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "The Red Hat Security Response Team has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 3, 4, or 5.",
"lastModified": "2008-05-29T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}