CVE-2024-52522

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-52522
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-52522.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-52522
Aliases
Related
Published
2024-11-15T18:15:30Z
Modified
2024-11-19T17:59:14.612889Z
Summary
[none]
Details

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

References

Affected packages

Debian:11 / rclone

Package

Name
rclone
Purl
pkg:deb/debian/rclone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.53.3-1
1.53.3-2
1.53.3-3
1.53.3-4
1.60.1+dfsg-1
1.60.1+dfsg-2
1.60.1+dfsg-3
1.60.1+dfsg-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / rclone

Package

Name
rclone
Purl
pkg:deb/debian/rclone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.60.1+dfsg-2
1.60.1+dfsg-3
1.60.1+dfsg-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / rclone

Package

Name
rclone
Purl
pkg:deb/debian/rclone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.60.1+dfsg-2
1.60.1+dfsg-3
1.60.1+dfsg-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/rclone/rclone

Affected ranges

Type
GIT
Repo
https://github.com/rclone/rclone
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.90
v0.91
v0.92
v0.93
v0.94
v0.95
v0.96
v0.97
v0.98
v0.99

v1.*

v1.00
v1.01
v1.03
v1.04
v1.05
v1.06
v1.07
v1.08
v1.09
v1.10
v1.11
v1.12
v1.13
v1.14
v1.15
v1.16
v1.17
v1.18
v1.19
v1.20
v1.21
v1.22
v1.23
v1.24
v1.25
v1.26
v1.27
v1.28
v1.29
v1.29-1-gbb75d80
v1.30
v1.31
v1.32
v1.33
v1.34
v1.35
v1.36
v1.37
v1.38
v1.39
v1.40
v1.41
v1.42
v1.43
v1.44
v1.45
v1.46
v1.46.0
v1.47.0
v1.48.0
v1.49.0
v1.50.0
v1.51.0
v1.52.0
v1.53.0
v1.54.0
v1.55.0
v1.56.0
v1.57.0
v1.58.0
v1.59.0
v1.60.0
v1.61.0
v1.62.0
v1.63.0
v1.64.0
v1.65.0
v1.66.0
v1.67.0
v1.68.0