CVE-2024-7773: Remote Code Execution via ZipSlip in ollama/ollama
Rejected reason: REJECT DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-45436. Notes: All CVE users should reference CVE-2024-45436 instead of this CVE Record. All references and descriptions in this candidate have been removed to prevent accidental usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7773?
CVE-2024-7773 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2024-7773?
To fix CVE-2024-7773, update to a patched version of Ollama that addresses the input validation issue.
What causes CVE-2024-7773?
CVE-2024-7773 is caused by improper input validation in the handling of zip files in the parseFromZipFile function.
Which versions of Ollama are affected by CVE-2024-7773?
Ollama version 0.1.37 is specifically affected by CVE-2024-7773.
Can CVE-2024-7773 be exploited remotely?
Yes, CVE-2024-7773 can be exploited remotely, allowing attackers to execute arbitrary code.