CVE-2021-24031

MEDIUM

Zstandard < 1.4.1 - Insecure Inherited Permissions

Title source: llm
STIX 2.1

Description

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/facebook/zstd/issues/1630
Exploit, Issue Tracking, Mailing List, Third Party Advisory x_refsource_misc
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=981404

Scores

CVSS v3 5.5
EPSS 0.0043
EPSS Percentile 34.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-277 CWE-276
Status published
Products (1)
facebook/zstandard < 1.4.1
Published Mar 04, 2021
Tracked Since Feb 18, 2026