CVE-2021-24032

Published: 20 February 2021

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Priority

Medium

CVSS 3 base score: 9.1

Status

Package Release Status
libzstd
Launchpad, Ubuntu, Debian
Upstream
Released (1.4.8+dfsg-2)
Ubuntu 21.04 (Hirsute Hippo) Pending
(1.4.8+dfsg-2build1)
Ubuntu 20.10 (Groovy Gorilla)
Released (1.4.5+dfsg-4ubuntu0.1)
Ubuntu 20.04 LTS (Focal Fossa)
Released (1.4.4+dfsg-3ubuntu0.1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1.3.3+dfsg-2ubuntu1.2)
Ubuntu 16.04 LTS (Xenial Xerus) Needs triage

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

Patches:
Upstream: https://github.com/felixhandte/zstd/commit/a774c5797399040af62db21d8a9b9769e005430e