CVE-2021-24032 PUBLISHED

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

EPSS 0.02% · 5.2th percentile

Risk Scores

EPSS Score
0.02%
5.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlibzstd0, 0.4.5-1, 0.5.1-1
Ubuntu:20.04:LTSlibzstd1.4.4+dfsg-3, 0, 1.4.3+dfsg-1
Ubuntu:18.04:LTSlibzstd1.3.3+dfsg-1, 1.3.3+dfsg-1ubuntu1, 1.3.3+dfsg-2ubuntu1

Timeline

References

Open in Interactive Console →