Facebook · Zstandard · CVE-2021-24032
Name of the Vulnerable Software and Affected Versions:
Zstandard command-line utility versions 1.4.1 through 1.4.9
Description:
The issue arises from an incomplete fix, resulting in output files being created with default permissions before being restricted. This momentary lapse allows unintended parties to potentially read or write to these files.
Recommendations:
For versions 1.4.1 through 1.4.9, consider updating to a version that fully addresses the issue, ensuring output files are created with appropriate permissions from the outset, thus preventing unintended access.