ollama News Articles
Recent news articles refferecing the vendors vulnerabilities.
Security firms debate CVE credit in overlapping vulnerability reports
FuzzingLabs has accused the YCombinator-backed startup, Gecko Security, of replicating its vulnerability disclosures. Gecko allegedly filed for 2 CVEs based on FuzzingLabs' reports without crediting them. Gecko denies any wrongdoing, calling the allegations a misunderstanding over disclosure process...
1 day ago
Security firms dispute credit for overlapping CVE reports
FuzzingLabs has accused the YCombinator-backed startup, Gecko Security, of replicating its vulnerability disclosures. Gecko allegedly filed for 2 CVEs based on FuzzingLabs' reports without crediting them. Gecko denies any wrongdoing, calling the allegations a misunderstanding over disclosure process...
1 day ago

Ollama AI Platform Flaw Let Attackers Execute Remote Code
Hackers attack AI infrastructure platforms since these systems contain a multitude of valuable data, algorithms that are sophisticated in
Исследователи выявили серьёзную уязвимость в открытой платформе искусственного интеллекта Ollama
Недостаток безопасности был выявлен компанией Wiz, занимающейся облачной безопасностью.

Ollama patches critical vulnerability in open-source AI-framework
The vulnerability could leave AI inference servers open to remote code execution that would allow them to be taken over.
Patch now: 'Easy-to-exploit' RCE in open source Ollama
A now-patched vulnerability in Ollama – a popular open source project for running LLMs – can lead to remote code execution, according to flaw finders who warned that upwards of 1,000 vulnerable instances...

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
Critical security flaw (CVE-2024-37032) discovered in Ollama, an open-source AI platform, could lead to remote code execution.

Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations | Wiz Blog
Wiz Research discovered CVE-2024-37032, an easy-to-exploit Remote Code Execution vulnerability in the open-source AI Infrastructure project Ollama.