VDB
ALPINE-CVE-2021-24032
ALPINE-CVE-2021-24032
PUBLISHED
CVSS 4.699999809265137 MEDIUM
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.
Risk Scores
CVSS v3.1
4.699999809265137
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.11 | zstd | 1.3.5-r0, 1.3.4-r0, 1.3.3-r1 |
| Alpine:v3.15 | zstd | 1.3.2-r0, 0, 1.1.4-r0 |
| Alpine:v3.23 | zstd | 1.1.3-r0, 1.4.8-r0, 1.4.5-r3 |
| Alpine:v3.16 | zstd | 1.1.3-r0, 1.3.3-r0, 1.3.4-r0 |
| Alpine:v3.21 | zstd | 1.4.3-r0, 1.1.1-r0, 1.1.3-r0 |
| Alpine:v3.14 | zstd | 1.3.1-r0, 1.3.2-r0, 1.3.3-r0 |
| Alpine:v3.18 | zstd | 1.4.3-r0, 1.4.8-r0, 1.2.0-r0 |
| Alpine:v3.13 | zstd | 1.4.4-r0, 1.4.8-r0, 1.4.5-r3 |
| Alpine:v3.12 | zstd | 1.3.3-r0, 1.4.4-r0, 1.4.4-r1 |
| Alpine:v3.22 | zstd | 1.3.7-r1, 1.3.7-r0, 1.3.5-r0 |
| Alpine:v3.20 | zstd | 1.4.2-r0, 1.1.1-r0, 1.2.0-r0 |
| Alpine:v3.19 | zstd | 1.1.3-r0, 1.1.4-r0, 1.3.0-r0 |
| Alpine:v3.17 | zstd | 0, 0, 1.1.3-r0 |
Timeline
- Mar 4, 2021 CVE Published
- Dec 3, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch