File Permission Vulnerability in Zstandard Utility by Facebook
CVE-2021-24031

5.5MEDIUM

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
4 March 2021

What is CVE-2021-24031?

The Zstandard command-line utility versions prior to 1.4.1 exhibit a flaw where output files are generated with default permissions. This means that until the process is fully completed, these files may inadvertently be accessible to unauthorized users. Specifically, the final permissions, which are intended to match those of the input files, are not correctly applied until the operation is finished. As a result, there is a risk of sensitive data exposure or accidental modification by unintended parties.

Affected Version(s)

Zstandard < 1.4.1

Zstandard 1.4.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.