Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffqj-7pgc-cmj5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

EPSS

Процентиль: 4%
0.0002
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 5 лет назад

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

CVSS3: 5.5
redhat
почти 5 лет назад

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

CVSS3: 4.7
nvd
почти 5 лет назад

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

CVSS3: 4.7
msrc
около 1 года назад

Описание отсутствует

CVSS3: 4.7
debian
почти 5 лет назад

Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for ...

EPSS

Процентиль: 4%
0.0002
Низкий

Дефекты

CWE-276