ALT-PU-2024-13759-3
Closed vulnerabilities
Published: 2024-10-23
BDU:2024-08371
Уязвимость функции extractFromZipFile() пакета model.go системы для запуска и управления большими языковыми моделями (LLM) Ollama, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации
Severity: CRITICAL (9.1)Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: CRITICAL (9.4)Vector: AV:N/AC:L/Au:N/C:C/I:C/A:N
References:
Published: 2024-08-29
Modified: 2024-08-30
Modified: 2024-08-30
CVE-2024-45436
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.
Severity: HIGH (7.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
Published: 2024-08-29
Modified: 2024-08-29
Modified: 2024-08-29
GHSA-846m-99qv-67mg
Ollama can extract members of a ZIP archive outside of the parent directory
Severity: HIGH (8.7)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity: HIGH (8.7)Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
References:
