Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-zstd | Mar 26, 2024 | Mar 4, 2021 | |
| Debian | debian-upgrade-libzstd | Mar 3, 2021 | Mar 3, 2021 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-libzstdhuawei-euleros-2_0_sp8-upgrade-libzstd-develhuawei-euleros-2_0_sp8-upgrade-zstd | Sep 24, 2021 | Mar 4, 2021 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-zstd | Aug 10, 2021 | Mar 4, 2021 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 4, 2021 |
| Suse | — | suse-upgrade-libzstd-develsuse-upgrade-libzstd-devel-staticsuse-upgrade-libzstd1suse-upgrade-libzstd1-32bitsuse-upgrade-zstd | Mar 29, 2021 | Mar 4, 2021 |
| Ubuntu | ubuntu-pro-upgrade-libzstd1ubuntu-pro-upgrade-zstdubuntu-upgrade-libzstd1ubuntu-upgrade-zstd | Mar 9, 2021 | Mar 4, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Mar 4, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub