¡¾Îó²îͨ¸æ¡¿OllamaÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2024-39720£©
Ðû²¼Ê±¼ä 2024-11-04Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | OllamaÔ½½ç¶ÁÈ¡Îó²î | ||
CVE ID | CVE-2024-39720 | ||
Îó²îÀàÐÍ | Ô½½ç¶ÁÈ¡ | ·¢Ã÷ʱ¼ä | 2024-11-04 |
Îó²îÆÀ·Ö | 8.2 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
OllamaÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢¡¢Ò×ÓÚʹÓÃÇÒÖ§³Ö¶àÖÖ´óÐÍÓïÑÔÄ£×Ӻͻúеѧϰ¿ò¼ÜµÄ¿ªÔ´¿ò¼Ü£¬£¬£¬£¬£¬£¬Ëü¼«´óµØ¼ò»¯ÁË´óÐÍÓïÑÔÄ£×ÓÔÚÍâµØ°²ÅźÍÖÎÀíµÄÀú³Ì£¬£¬£¬£¬£¬£¬ÎªÑо¿ºÍ¿ª·¢Ö°Ô±ÌṩÁ˼«´óµÄ±ãµ±¡£¡£¡£
2024Äê11ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½OllamaÖб»Åû¶±£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ýHTTPÇëÇóÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜÔì³É¾Ü¾øÐ§ÀÍ¡¢ÐÅϢй¶µÈ£¬£¬£¬£¬£¬£¬ÏÖÔÚÕâЩÎó²îµÄÊÖÒÕϸ½ÚÒѹûÕæ£¬£¬£¬£¬£¬£¬²¿·ÖÎó²îÏêÇéÈçÏ£º
CVE-2024-39720£ºOllamaÔ½½ç¶ÁÈ¡Îó²î
Ollama °æ±¾ <= 0.1.45Öб£´æÔ½½ç¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.2£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ýÁ½¸öHTTP POSTÇëÇóÉÏ´«Ò»¸öÌØÖÆµÄGGUFÎļþ£¬£¬£¬£¬£¬£¬¸ÃÎļþ½ö°üÀ¨4¸ö×Ö½Ú£¬£¬£¬£¬£¬£¬²¢ÒÔGGUF×Ô½ç˵µÄаÊõ±êÍ·¿ªÍ·¡£¡£¡£¹¥»÷Õß½øÒ»²½Ê¹ÓÃÒ»¸ö°üÀ¨Ö¸ÏòÆä¿ØÖƵÄblobÎļþµÄFROMÓï¾äµÄ×Ô½ç˵Modelfile£¬£¬£¬£¬£¬£¬Í¨¹ý/api/create·ÓɵÄCreateModel¹¦Ð§£¬£¬£¬£¬£¬£¬Ê¹Ó¦ÓóÌÐòÔÚ´¦Öóͷ£¸Ã¶ñÒâÇëÇóʱ±¬·¢Í߽⣬£¬£¬£¬£¬£¬Òý·¢·Ö¶Î¹ýʧ£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©¡£¡£¡£
CVE-2024-39722£ºOllamaÐÅϢй¶Îó²î
Ollama°æ±¾<=0.1.45ÖÐapi/push·Óɱ£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏò¸Ã·ÓÉ·¢ËͰüÀ¨¶ñÒâ½á¹¹µÄ¡¢²»±£´æµÄ·¾¶²ÎÊýµÄPOSTÇëÇóÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂЧÀÍÆ÷·µ»Ø°üÀ¨ÎļþϵͳÐÅÏ¢µÄ¹ýʧÐÂÎÅ£¬£¬£¬£¬£¬£¬Ð¹Â¶ÆäÎļþĿ¼½á¹¹¡£¡£¡£
CVE-2024-39719£ºOllamaÐÅϢй¶Îó²î
Ollama°æ±¾<= 0.3.14Öб£´æÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬£¬ÓÉÓÚapi/create·ÓÉÖжÔ·¾¶²ÎÊý´¦Öóͷ£²»µ±£¬£¬£¬£¬£¬£¬ÈôÊǹ¥»÷ÕßʹÓÃPOSTÒªÁìÏò¸Ã·ÓÉ·¢ËͰüÀ¨²»±£´æµÄÎļþ·¾¶²ÎÊýµÄ¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Ó¦ÓóÌÐò»á·µ»ØÒ»¸ö°üÀ¨Îļþ²»±£´æµÄ¹ýʧÏìÓ¦£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜй¶ЧÀÍÆ÷ÉÏÎļþµÄ±£´æÐÔÐÅÏ¢¡£¡£¡£
CVE-2024-39721£ºOllama¾Ü¾øÐ§ÀÍÎó²î
Ollama°æ±¾<= 0.1.33Öб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬£¬ÓÉÓÚapi/create·ÓɵÄCreateModelHandlerº¯Êýδ¶ÔÓû§¿ØÖƵÄreq.Path²ÎÊý¾ÙÐÐÊʵ±ÑéÖ¤£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖ¸¶¨Èç/dev/randomÕâÑùµÄÌØÊâÎļþ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏò¸Ã·ÓÉ·¢ËͰüÀ¨´ËÀàÌØÊâÎļþ·¾¶µÄPOSTÇëÇóÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬µ¼Ö³ÌÐòÔÚ¶ÁÈ¡ÎļþʱÛÕ±Õ£¬£¬£¬£¬£¬£¬´Ó¶ø½øÈëÎÞÏÞÑ»·£¬£¬£¬£¬£¬£¬×îÖÕµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
CVE | Ó°Ïì¹æÄ£ | ÐÞ¸´°æ±¾ |
CVE-2024-39720 | Ollama°æ±¾<= 0.1.45 | Ollama°æ±¾>=0.1.46 |
CVE-2024-39722 | Ollama°æ±¾<=0.1.45 | Ollama°æ±¾>=0.1.46 |
CVE-2024-39719 | Ollama°æ±¾<= 0.3.14 | ÉÐδÐÞ¸´ |
CVE-2024-39721 | Ollama°æ±¾<= 0.1.33 | Ollama°æ±¾>=0.1.34 |
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ²¿·ÖÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿É²Î¿¼ÉϱíÉý¼¶µ½ÏìÓ¦ÐÞ¸´°æ±¾»ò×îа汾¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://github.com/ollama/ollama/releases
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://www.oligo.security/blog/more-models-more-probllms
https://nvd.nist.gov/vuln/detail/CVE-2024-39720
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-11-04 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º