Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29873
HistoryMar 31, 2021 - 7:59 a.m.

Insecure File Permission

2021-03-3107:59:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.0005 Low

EPSS

Percentile

17.2%

libzstd.so uses insecure file permissions. The vulnerability exists due to default file permissions(0600) used in Zstandard command-line utility when compressing or uncompressing input files. This causes a race condition whereby an attacker will be able to access and modify affected files.