
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2021-24031) affects the Zstandard command-line utility prior to version 1.4.1. The issue involves the creation of output files with default permissions during compression operations, potentially exposing sensitive data. The vulnerability was discovered and reported in early 2021, affecting systems using the Zstandard compression utility (NVD, Debian Bug).
When compressing files with restricted access permissions, the Zstandard utility would temporarily create the output file with default permissions (typically world-readable) before applying the intended permissions. This created a race condition where the file could be accessed by unauthorized users during the compression process. The issue was particularly concerning when handling sensitive files with restricted permissions (Debian Bug).
The vulnerability could allow local attackers to access sensitive data during the compression process. Even if the source file had restricted permissions (e.g., 600), the compressed output file would temporarily be created with more permissive access rights (e.g., 644), potentially exposing confidential information to unauthorized users (Debian Bug).
The vulnerability could be exploited by a local attacker who could open the file while zstd was still running and wait for the compression to complete, thereby gaining access to potentially sensitive data. The exploit required local system access and precise timing to take advantage of the race condition (Debian Bug).
The issue was fixed in Zstandard version 1.4.1 and later releases. The fix ensures that output files are created with appropriate permissions matching the source file. For affected versions, users should upgrade to version 1.4.1 or later. System administrators can also implement additional access controls to restrict access to directories where compression operations occur (NVD, Debian Bug).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."