rclone: Weak random number generation — GLSA 202107-14

rclone uses weak random number generation such that generated passwords can be easily cracked.

Affected packages

net-misc/rclone on all architectures
Affected versions < 1.53.3
Unaffected versions >= 1.53.3

Background

rclone is a problem to sync files to and from various cloud storage providers.

Description

Passwords generated with rclone were insecurely generated and are vulnerable to brute force attacks.

Impact

Data kept secret with a password generated by rclone may be disclosed to a local attacker.

Workaround

There is no known workaround at this time.

Resolution

All rclone users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-misc/rclone-1.53.3"
 

References

Release date
July 08, 2021

Latest revision
July 08, 2021: 1

Severity
normal

Exploitable
local

Bugzilla entries