Incorrect default permissions in Zstandard - CVE-2021-24032

 

Incorrect default permissions in Zstandard - CVE-2021-24032

Published: March 23, 2021


Vulnerability identifier: #VU51640
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-24032
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for files and folders that are set by the application within the command-line utility. A remote attacker can view contents of files and directories or modify them.


Affected software

Zstandard
cflinuxfs3
SUSE MicroOS
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
CF Deployment
zstd (Ubuntu package)
libzstd1 (Ubuntu package)
libzstd1-debuginfo
libzstd1-32bit-debuginfo
libzstd1-32bit
zstd
libzstd-devel
zstd-debugsource
zstd-debuginfo
libzstd1
zstd-devel
zstd-help
AMQ Streams

How to mitigate CVE-2021-24032

Install updates from vendor's website.

Zstandard - update to 1.4.9
cflinuxfs3 - update to 0.228.0
CF Deployment - update to 16.7.0
zstd (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.3+dfsg-2ubuntu1.2, 1.4.4+dfsg-3ubuntu0.1, 1.4.5+dfsg-4ubuntu0.1
libzstd1 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.3+dfsg-2ubuntu1.2, 1.4.4+dfsg-3ubuntu0.1, 1.4.5+dfsg-4ubuntu0.1
libzstd1-debuginfo - update to 1.4.4-1.6.1
libzstd1-32bit-debuginfo - update to 1.4.4-1.6.1
libzstd1-32bit - update to 1.4.4-1.6.1
zstd - update to 1.4.4-1.6.1
libzstd-devel - update to 1.4.4-1.6.1
zstd-debugsource - update to 1.4.4-1.6.1
zstd-debuginfo - update to 1.4.4-1.6.1
libzstd1 - update to 1.4.4-1.6.1
zstd - update to 1.4.5-1
zstd-debuginfo - update to 1.4.5-1
zstd-debugsource - update to 1.4.5-1
zstd-devel - update to 1.4.5-1
zstd-help - update to 1.4.5-1
AMQ Streams - update to 2.7.0

External References

Related Security Bulletins