[ GLSA 202107-14 ] rclone: Weak random number generation

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <[email protected]>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202107-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: rclone: Weak random number generation
     Date: July 08, 2021
     Bugs: #755638
       ID: 202107-14

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

rclone uses weak random number generation such that generated passwords
can be easily cracked.

Background
==========

rclone is a problem to sync files to and from various cloud storage
providers.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  net-misc/rclone              < 1.53.3                  >= 1.53.3 

Description
===========

Passwords generated with rclone were insecurely generated and are
vulnerable to brute force attacks.

Impact
======

Data kept secret with a password generated by rclone may be disclosed
to a local attacker.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All rclone users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=net-misc/rclone-1.53.3"

References
==========

[ 1 ] CVE-2020-28924
      https://nvd.nist.gov/vuln/detail/CVE-2020-28924

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202107-14

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2021 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEElFuPenBj6NvNLoABXP0dAeB+IzgFAmDmcJsACgkQXP0dAeB+
Izj4hw//fB8R352ycpwSa8pGFESvv3gGK+08Pz3tCb9dGsmafdzd/Z4CCTIF8RI1
YgjniEzLTu644BNXEkpSjs/DF/yq7PzyKa1Xt4dQpjojir3tu/rk8uWyrMeZb6Yu
4eTRxXuONachsMP7E8NbpY6NZCbF6iwYTJTLsFgcwOgWleUPSeS8pOmLIKVgW86n
snr1hqfNhbHf9mCwb091LpCb1tO+8WXpUnxLuAmJC7N8cnGbDHmWquFrJh4yj9B6
xnrC/x1yJQH5RJZ/D/peoeTpB8kFBZxBlNljSi6HMReCp7LYoBKeRHK3b3eHxcqP
HMRdP8e3MhWra9VZCAIn1tGIdGJ8BuqSLIOO9nMcm2sO8Ccv3D5EHRTLs0CDQwIK
NAG4kf/gQN6FoFk7GyKlaZ5KEyokoE1JMvwLVbOYxz6oJiqsyHagYi/j7BzR2UxA
0aJDJiBlZ1OWpK8pSMQzFa3FDzkzZtAATQOoBbCFs34qUtLtCSMMAuyDnDChZDg9
d65CPbltI1Z763xOFHY+lwqz1qcXsT3GKZhpVFW1eU6cRonfdAy8XEBeGIYvhPUd
fIm8agUjZqXxvRr8ugghNiMZ5Jkabto3rvkHgwGtcq0X9pri0N74Ff1YiI8Y5PQQ
EKOnxjFaOH6YEGnxIGMfjPYk+hPyE+8jCdlF60jVB7kKTS5lUP0=
=KW6e
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.