CVE-2024-39720
CVE-2024-39720
Título es
CVE-2024-39720
Jue, 31/10/2024 – 20:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-39720
Descripción en
An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).
31/10/2024
31/10/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off