{"id":"MGASA-2021-0322","summary":"Updated zstd packages fix a security vulnerability","details":"In the Zstandard command-line utility prior to v1.4.1, output files were\ncreated with default permissions. Correct file permissions (matching the input)\nwould only be set at completion time. Output files could therefore be readable\nor writable to unintended parties (CVE-2021-24031).\n","modified":"2026-04-16T04:43:52.589447283Z","published":"2021-07-09T00:27:08Z","upstream":["CVE-2021-24031"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0322.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28444"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4760-1"}],"affected":[{"package":{"name":"zstd","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/zstd?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.0-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0322.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}