5.6 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
ignored
22 packages
- gollama
- ollama-cpu
- nextjs-ollama-llm-ui
- python312Packages.ollama
- python313Packages.ollama
- python314Packages.ollama
- python312Packages.llm-ollama
- python313Packages.llm-ollama
- python314Packages.llm-ollama
- haskellPackages.ollama-haskell
- gnomeExtensions.ollama-indicator
- python312Packages.langchain-ollama
- python313Packages.langchain-ollama
- python314Packages.langchain-ollama
- home-assistant-component-tests.ollama
- tests.home-assistant-components.ollama
- python312Packages.llama-index-llms-ollama
- python313Packages.llama-index-llms-ollama
- python312Packages.llama-index-embeddings-ollama
- python313Packages.llama-index-embeddings-ollama
- pkgsRocm.python3Packages.llama-index-llms-ollama
- pkgsRocm.python3Packages.llama-index-embeddings-ollama
- @LeSuisse restored package ollama-cpu
- @LeSuisse ignored
- @LeSuisse accepted
- @LeSuisse published on GitHub
Ollama Tensor Model Transfer transfer.go digestToPath path traversal
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
References
Ignored references (3)
-
Submit #797576 | Ollama v0.20.2 Information Disclosure third-party-advisory
-
-
VDB-359599 | Ollama Tensor Model Transfer transfer.go digestToPath path traversal vdb-entrytechnical-description
Affected products
- ==0.20.1
- ==0.20.2
- ==0.20.0
Matching in nixpkgs
pkgs.ollama
Get up and running with large language models locally
pkgs.ollama-cpu
Get up and running with large language models locally
pkgs.ollama-cuda
Get up and running with large language models locally, using CUDA for NVIDIA GPU acceleration
pkgs.ollama-rocm
Get up and running with large language models locally, using ROCm for AMD GPU acceleration
pkgs.ollama-vulkan
Get up and running with large language models locally, using Vulkan for generic GPU acceleration
Ignored packages (21)
pkgs.gollama
Go manage your Ollama models
pkgs.nextjs-ollama-llm-ui
Simple chat web interface for Ollama LLMs
pkgs.python312Packages.ollama
Ollama Python library
pkgs.python313Packages.ollama
Ollama Python library
pkgs.python314Packages.ollama
Ollama Python library
pkgs.python312Packages.llm-ollama
LLM plugin providing access to Ollama models using HTTP API
pkgs.python313Packages.llm-ollama
LLM plugin providing access to Ollama models using HTTP API
pkgs.python314Packages.llm-ollama
LLM plugin providing access to Ollama models using HTTP API
pkgs.haskellPackages.ollama-haskell
Haskell client for ollama
pkgs.gnomeExtensions.ollama-indicator
An indicator that let you run models with Ollama.
pkgs.python312Packages.langchain-ollama
Integration package connecting Ollama and LangChain
pkgs.python313Packages.langchain-ollama
Integration package connecting Ollama and LangChain
pkgs.python314Packages.langchain-ollama
Integration package connecting Ollama and LangChain
pkgs.home-assistant-component-tests.ollama
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-components.ollama
Open source home automation that puts local control and privacy first
pkgs.python312Packages.llama-index-llms-ollama
LlamaIndex LLMS Integration for ollama
pkgs.python313Packages.llama-index-llms-ollama
LlamaIndex LLMS Integration for ollama
Package maintainers
-
@dit7ya Mostly Void <7rat13@gmail.com>
-
@prusnak Pavol Rusnak <pavol@rusnak.io>
-
@abysssol abysssol <abysssol@pm.me>