File Permission Vulnerability in Zstandard Utility by Facebook
CVE-2021-24031
5.5MEDIUM
What is CVE-2021-24031?
The Zstandard command-line utility versions prior to 1.4.1 exhibit a flaw where output files are generated with default permissions. This means that until the process is fully completed, these files may inadvertently be accessible to unauthorized users. Specifically, the final permissions, which are intended to match those of the input files, are not correctly applied until the operation is finished. As a result, there is a risk of sensitive data exposure or accidental modification by unintended parties.
Affected Version(s)
Zstandard < 1.4.1
Zstandard 1.4.1