openSUSE-SU-2021:0481-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0481-1
openSUSE-SU-2021:0481-1
Summary: Security update for zstd
Details: This update for zstd fixes the following issues: - CVE-2021-24031: Added read permissions to files while being compressed or uncompressed (bsc#1183371). - CVE-2021-24032: Fixed a race condition which could have allowed an attacker to access world-readable destination file (bsc#1183370). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/HYCURYHE4SZBA5XWHE6FDNCJ3JJDZS5S/, https://bugzilla.suse.com/1183370, https://bugzilla.suse.com/1183371, https://www.suse.com/security/cve/CVE-2021-24031, https://www.suse.com/security/cve/CVE-2021-24032
Affected packages
Package
Name: zstd
Purl: pkg:rpm/opensuse/zstd&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
