An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ollama
Ollama ollama |
|
Weaknesses | CWE-125 | |
CPEs | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ollama
Ollama ollama |
|
Metrics |
cvssV3_1
|
Fri, 01 Nov 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 01 Nov 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 31 Oct 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation). | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-31T00:00:00
Updated: 2024-11-01T15:20:12.939Z
Reserved: 2024-06-28T00:00:00
Link: CVE-2024-39720
Vulnrichment
Updated: 2024-11-01T15:20:03.231Z
NVD
Status : Awaiting Analysis
Published: 2024-10-31T20:15:04.877
Modified: 2024-11-01T16:35:23.210
Link: CVE-2024-39720
Redhat
No data.