CVE-2024-37032

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-37032
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37032.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-37032
Aliases
Related
Published
2024-05-31T04:15:09Z
Modified
2025-05-01T14:53:57.127304Z
Summary
[none]
Details

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.

References

Affected packages

Git / github.com/ollama/ollama

Affected ranges

Type
GIT
Repo
https://github.com/ollama/ollama
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.0.1
v0.0.10
v0.0.11
v0.0.12
v0.0.13
v0.0.14
v0.0.15
v0.0.16
v0.0.17
v0.0.18
v0.0.19
v0.0.2
v0.0.20
v0.0.21
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.13
v0.1.14
v0.1.15
v0.1.16
v0.1.17
v0.1.18
v0.1.19
v0.1.2
v0.1.20
v0.1.21
v0.1.22
v0.1.23
v0.1.24
v0.1.25
v0.1.26
v0.1.27
v0.1.28
v0.1.29
v0.1.3
v0.1.30
v0.1.32
v0.1.32-rc1
v0.1.32-rc2
v0.1.33
v0.1.33-rc1
v0.1.33-rc2
v0.1.33-rc3
v0.1.33-rc4
v0.1.33-rc5
v0.1.33-rc6
v0.1.33-rc7
v0.1.34-rc1
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9