ZeroHour

CVE-2021-24032

CVSS 3.1
4.7 medium
EPSS
<1%p28
Published
()
Modified
Description

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Vendors
facebook
Products
zstandard
Weakness
CWE-277, CWE-276
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.