All errata/p9/ALT-PU-2019-2551-1
ALT-PU-2019-2551-1

Package update zstd in branch p9

Version1.4.2-alt1
Published2019-08-28
Max severityMEDIUM
Severity:

Closed issues (1)

CVE-2021-24031
MEDIUM5.5

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

Published: 2021-03-04Modified: 2024-11-21
CVSS 2.0LOW 2.1
CVSS:2.0/AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N