Skip to content

Commit bc2a31f

Browse files
thatnealpatelgopherbot
authored andcommitted
data/reports: add 4 reports
- data/reports/GO-2025-3548.yaml - data/reports/GO-2025-3557.yaml - data/reports/GO-2025-3558.yaml - data/reports/GO-2025-3559.yaml Updates #3548 Updates #3557 Updates #3558 Updates #3559 Change-Id: Iacc79cac5755612918f95062b7917700630c3a3e Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/661355 Reviewed-by: Damien Neil <[email protected]> LUCI-TryBot-Result: Go LUCI <[email protected]> Auto-Submit: Neal Patel <[email protected]>
1 parent ced2a51 commit bc2a31f

8 files changed

+256
-0
lines changed

data/osv/GO-2025-3548.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3548",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2024-12886",
8+
"GHSA-v464-r2r9-www7"
9+
],
10+
"summary": "Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP in github.com/ollama/ollama",
11+
"details": "Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP in github.com/ollama/ollama",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/ollama/ollama",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
}
30+
],
31+
"references": [
32+
{
33+
"type": "ADVISORY",
34+
"url": "https://github.com/advisories/GHSA-v464-r2r9-www7"
35+
},
36+
{
37+
"type": "WEB",
38+
"url": "https://huntr.com/bounties/f115fe52-58af-4844-ad29-b1c25f7245df"
39+
}
40+
],
41+
"database_specific": {
42+
"url": "https://pkg.go.dev/vuln/GO-2025-3548",
43+
"review_status": "REVIEWED"
44+
}
45+
}

data/osv/GO-2025-3557.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3557",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-0315",
8+
"GHSA-fccc-8m69-8r78"
9+
],
10+
"summary": "Ollama Allocation of Resources Without Limits or Throttling vulnerability in github.com/ollama/ollama",
11+
"details": "Ollama Allocation of Resources Without Limits or Throttling vulnerability in github.com/ollama/ollama",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/ollama/ollama",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
}
30+
],
31+
"references": [
32+
{
33+
"type": "ADVISORY",
34+
"url": "https://github.com/advisories/GHSA-fccc-8m69-8r78"
35+
},
36+
{
37+
"type": "WEB",
38+
"url": "https://huntr.com/bounties/da414d29-b55a-496f-b135-17e0fcec67bc"
39+
}
40+
],
41+
"database_specific": {
42+
"url": "https://pkg.go.dev/vuln/GO-2025-3557",
43+
"review_status": "REVIEWED"
44+
}
45+
}

data/osv/GO-2025-3558.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3558",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2024-12055",
8+
"GHSA-89qx-m49c-8crf"
9+
],
10+
"summary": "Ollama Allows Out-of-Bounds Read in github.com/ollama/ollama",
11+
"details": "Ollama Allows Out-of-Bounds Read in github.com/ollama/ollama",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/ollama/ollama",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
}
30+
],
31+
"references": [
32+
{
33+
"type": "ADVISORY",
34+
"url": "https://github.com/advisories/GHSA-89qx-m49c-8crf"
35+
},
36+
{
37+
"type": "WEB",
38+
"url": "https://huntr.com/bounties/7b111d55-8215-4727-8807-c5ed4cf1bfbe"
39+
}
40+
],
41+
"database_specific": {
42+
"url": "https://pkg.go.dev/vuln/GO-2025-3558",
43+
"review_status": "REVIEWED"
44+
}
45+
}

data/osv/GO-2025-3559.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3559",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-0317",
8+
"GHSA-9gcr-28rp-cc24"
9+
],
10+
"summary": "Ollama Divide By Zero vulnerability in github.com/ollama/ollama",
11+
"details": "Ollama Divide By Zero vulnerability in github.com/ollama/ollama",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/ollama/ollama",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
}
30+
],
31+
"references": [
32+
{
33+
"type": "ADVISORY",
34+
"url": "https://github.com/advisories/GHSA-9gcr-28rp-cc24"
35+
},
36+
{
37+
"type": "WEB",
38+
"url": "https://huntr.com/bounties/a9951bca-9bd8-49b2-b143-4cd4219f9fa0"
39+
}
40+
],
41+
"database_specific": {
42+
"url": "https://pkg.go.dev/vuln/GO-2025-3559",
43+
"review_status": "REVIEWED"
44+
}
45+
}

data/reports/GO-2025-3548.yaml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
id: GO-2025-3548
2+
modules:
3+
- module: github.com/ollama/ollama
4+
vulnerable_at: 0.6.3
5+
summary: |-
6+
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP in
7+
github.com/ollama/ollama
8+
cves:
9+
- CVE-2024-12886
10+
ghsas:
11+
- GHSA-v464-r2r9-www7
12+
references:
13+
- advisory: https://github.com/advisories/GHSA-v464-r2r9-www7
14+
- web: https://huntr.com/bounties/f115fe52-58af-4844-ad29-b1c25f7245df
15+
notes:
16+
- No patch has been published at this time.
17+
source:
18+
id: GHSA-v464-r2r9-www7
19+
created: 2025-03-27T14:47:34.822586-04:00
20+
review_status: REVIEWED

data/reports/GO-2025-3557.yaml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
id: GO-2025-3557
2+
modules:
3+
- module: github.com/ollama/ollama
4+
vulnerable_at: 0.6.3
5+
summary: |-
6+
Ollama Allocation of Resources Without Limits or Throttling vulnerability in
7+
github.com/ollama/ollama
8+
cves:
9+
- CVE-2025-0315
10+
ghsas:
11+
- GHSA-fccc-8m69-8r78
12+
references:
13+
- advisory: https://github.com/advisories/GHSA-fccc-8m69-8r78
14+
- web: https://huntr.com/bounties/da414d29-b55a-496f-b135-17e0fcec67bc
15+
notes:
16+
- No patch has been published at this time.
17+
source:
18+
id: GHSA-fccc-8m69-8r78
19+
created: 2025-03-27T14:47:45.518137-04:00
20+
review_status: REVIEWED

data/reports/GO-2025-3558.yaml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
id: GO-2025-3558
2+
modules:
3+
- module: github.com/ollama/ollama
4+
vulnerable_at: 0.6.3
5+
summary: Ollama Allows Out-of-Bounds Read in github.com/ollama/ollama
6+
cves:
7+
- CVE-2024-12055
8+
ghsas:
9+
- GHSA-89qx-m49c-8crf
10+
references:
11+
- advisory: https://github.com/advisories/GHSA-89qx-m49c-8crf
12+
- web: https://huntr.com/bounties/7b111d55-8215-4727-8807-c5ed4cf1bfbe
13+
notes:
14+
- No patch has been published at this time.
15+
source:
16+
id: GHSA-89qx-m49c-8crf
17+
created: 2025-03-27T14:47:52.319054-04:00
18+
review_status: REVIEWED

data/reports/GO-2025-3559.yaml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
id: GO-2025-3559
2+
modules:
3+
- module: github.com/ollama/ollama
4+
vulnerable_at: 0.6.3
5+
summary: Ollama Divide By Zero vulnerability in github.com/ollama/ollama
6+
cves:
7+
- CVE-2025-0317
8+
ghsas:
9+
- GHSA-9gcr-28rp-cc24
10+
references:
11+
- advisory: https://github.com/advisories/GHSA-9gcr-28rp-cc24
12+
- web: https://huntr.com/bounties/a9951bca-9bd8-49b2-b143-4cd4219f9fa0
13+
notes:
14+
- No patch has been published at this time.
15+
source:
16+
id: GHSA-9gcr-28rp-cc24
17+
created: 2025-03-27T14:47:58.941118-04:00
18+
review_status: REVIEWED

0 commit comments

Comments
 (0)