Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 24 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Meta Platforms Inc
Meta Platforms Inc llama Stack
CPEs cpe:2.3:a:meta_platforms_inc:llama_stack:*:*:*:*:*:*:*:*
Vendors & Products Meta Platforms Inc
Meta Platforms Inc llama Stack
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
Description Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published:

Updated: 2024-10-24T18:26:22.699Z

Reserved: 2024-10-21T15:18:52.624Z

Link: CVE-2024-50050

cve-icon Vulnrichment

Updated: 2024-10-24T18:26:08.699Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-23T14:15:05.087

Modified: 2024-10-24T19:35:08.107

Link: CVE-2024-50050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.