Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in rclone - CVE-2020-28924

 

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in rclone - CVE-2020-28924

Published: November 19, 2020 / Updated: November 20, 2020


Vulnerability identifier: #VU48568
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28924
CWE-ID: CWE-338
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to decrypt or brute-force passwords.

The vulnerability exists due to Rclone uses a weak random number generator for generating passwords with much less entropy than advertised. An attacker, who is able to obtain the password protected file can decrypt data.


Affected software

rclone
Arch Linux
Gentoo Linux
Fedora
rclone

How to mitigate CVE-2020-28924

Install updates from vendor's website.

rclone - update to 1.53.3
rclone - addressed in versions 1.53.3-1.el8, 1.53.3-1.fc33

External References

Related Security Bulletins