OllamaGHSA-846m-99qv-67mg
Ollama can extract members of a ZIP archive outside of the parent directory
High7.5CVE-2024-45436 · Published Aug 29, 2024 · updated Aug 30, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/ollama/ollama Go | < 0.1.47 | 0.1.47 |
Details and references
`extractFromZipFile` in `model.go` in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2024-45436, GO-2024-3104
More Ollama advisories
All Ollama| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 312024 | Ollama Out-of-bounds Read CVE-2024-39720High8.2fixed in 0.1.46 | High8.2 | 0.1.46 |
| May 312024 | Ollama does not validate the format of the digest (sha256 with 64 hex digits) CVE-2024-37032Mediumfixed in 0.1.34 | Medium | 0.1.34 |
| Apr 82024 | Ollama DNS rebinding vulnerability CVE-2024-28224High8.8fixed in 0.1.29 | High8.8 | 0.1.29 |
| Mar 202025 | Ollama Allows Out-of-Bounds Read CVE-2024-12055High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP CVE-2024-12886High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Divide by Zero Vulnerability CVE-2024-8063High7.5no fix yet | High7.5 | No fix yet |