Skip to content
OllamaGHSA-846m-99qv-67mg

Ollama can extract members of a ZIP archive outside of the parent directory

High7.5CVE-2024-45436 · Published Aug 29, 2024 · updated Aug 30, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
< 0.1.470.1.47
Details and references

`extractFromZipFile` in `model.go` in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2024-45436, GO-2024-3104

More Ollama advisories

All Ollama
DateAdvisory
Oct 312024Ollama Out-of-bounds Read
CVE-2024-39720High8.2fixed in 0.1.46
May 312024Ollama does not validate the format of the digest (sha256 with 64 hex digits)
CVE-2024-37032Mediumfixed in 0.1.34
Apr 82024Ollama DNS rebinding vulnerability
CVE-2024-28224High8.8fixed in 0.1.29
Mar 202025Ollama Allows Out-of-Bounds Read
CVE-2024-12055High7.5no fix yet
Mar 202025Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
CVE-2024-12886High7.5no fix yet
Mar 202025Ollama Divide by Zero Vulnerability
CVE-2024-8063High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.