Tag: Ollama AI

Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning
News

Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning

Six security holes in the Ollama artificial intelligence (AI) framework have been found by cybersecurity experts. These vulnerabilities might be used by a malevolent actor to carry out a variety of tasks, such as model poisoning, denial-of-service attacks, and model theft. According to a paper released last week by Oligo Security researcher Avi Lumelsky, the vulnerabilities used together might enable an attacker to perform a variety of harmful operations with a single HTTP request, such as model poisoning, model theft, denial-of-service (DoS) attacks, and more. Large language models (LLMs) can be installed and run locally on Windows, Linux, and macOS systems using the open-source Ollama application read more about Critical Flaws in Ollama AI Framework Could Enable DoS Model Theft an...
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
News

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

Researchers studying cybersecurity have identified a vulnerability that can be leveraged to accomplish remote code execution on the Ollama open-source artificial intelligence (AI) infrastructure platform. This vulnerability is currently fixed. Cloud security company Wiz has given the vulnerability, which is tracked as CVE-2024-37032, the codename Probllama. Version 0.1.34 was released on May 7, 2024, and it resolved the issue after responsible disclosure on May 5, 2024. Large language models (LLMs) can be packaged, deployed, and operated locally on Windows, Linux, and macOS devices using the Ollama service. Basically, the problem is a case of inadequate input validation that causes a path traversal vulnerability that an attacker might use to overwrite any file on the server and e...