CVE-2024-45436

HIGH7.5EPSS 29.1%

Ollama can extract members of a ZIP archive outside of the parent directory

Published: 8/29/2024Modified: 8/30/2024
Also known as:GHSA-846m-99qv-67mgGO-2024-3104

Description

`extractFromZipFile` in `model.go` in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (6)