CVE-2024-37032 Information
Jun 01, 2024
cve
Description
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits more than 64 hex digits or an initial ../ substring.
Reference
https://github.com/ollama/ollama/pull/4175 https://github.com/ollama/ollama/compare/v0.1.33…v0.1.34 https://github.com/ollama/ollama/blob/adeb40eaf29039b8964425f69a9315f9f1694ba8/server/modelpath_test.go#L41-L58
Share on: