Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2021-24032

Published: August 31, 2023Last modified: August 31, 2023

Description

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Severity score breakdown

ParameterValue
Base score4.7
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSzstdNot affected (1.5.5-r0)
StreamzstdNot affected (1.5.5-r5)

References

ON THIS PAGE