cve-2024-37032

csaf_suse
Description

SUSE CVE-2024-37032

Timeline
Published
2024-06-01 02:22 UTC
Last Modified
2026-08-26
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "SUSE CVE-2024-37032",
        "title": "Title"
      },
      {
        "category": "description",
        "text": "Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.",
        "title": "Description of the CVE"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "CVE-2024-37032",
        "url": "https://www.suse.com/security/cve/CVE-2024-37032"
      },
      {
        "category": "external",
        "summary": "SUSE Security Ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "external",
        "summary": "SUSE Bug 1225724 for CVE-2024-37032",
        "url": "https://bugzilla.suse.com/1225724"
      },
      {
        "category": "external",
        "summary": "Advisory link for openSUSE-SU-2024:14599-1",
        "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QTUY324RV3FFZBHVIWDHRCIOPJHIJIN4/"
      }
    ],
    "title": "SUSE CVE CVE-2024-37032",
    "tracking": {
      "current_release_date": "2026-08-26T01:37:01Z",
      "generator": {
        "date": "2024-06-01T02:22:42Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf-vex.pl",
          "version": "1"
        }
      },
      "id": "CVE-2024-37032",
      "initial_release_date": "2024-06-01T02:22:42Z",
      "revision_history": [
        {
          "date": "2024-06-01T02:22:42Z",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2024-12-19T04:08:15Z",
          "number": "3",
          "summary": "Current version"
        },
        {
          "date": "2024-12-20T04:05:14Z",
          "number": "4",
          "summary": "Current version"
        },
        {
          "date": "2025-02-14T04:54:52Z",
          "number": "5",
          "summary": "Current version"
        },
        {
          "date": "2025-02-16T04:47:03Z",
          "number": "6",
          "summary": "Current version"
        },
        {
          "date": "2025-03-15T05:02:30Z",
          "number": "7",
          "summary": "Current version"
        },
        {
          "date": "2025-03-29T03:29:16Z",
          "number": "8",
          "summary": "Current version"
        },
        {
          "date": "2025-11-03T01:46:18Z",
          "number": "9",
          "summary": "Current version"
        },
        {
          "date": "2026-01-16T00:45:57Z",
          "number": "10",
          "summary": "unknown changes"
        },
        {
          "date": "2026-03-11T18:41:02Z",
          "number": "11",
          "summary": "unknown changes"
        },
        {
          "date": "2026-03-13T14:48:14Z",
          "number": "12",
          "summary": "unknown changes"
        },
        {
          "date": "2026-07-16T19:11:47Z",
          "number": "13",
          "summary": "more updates released"
        },
        {
          "date": "2026-08-26T01:37:01Z",
          "number": "14",
          "summary": "more updates released"
        }
      ],
      "status": "interim",
      "version": "14"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 16.0",
                "product": {
                  "name": "SUSE Linux Enterprise Server 16.0",
                  "product_id": "SUSE Linux Enterprise Server 16.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.0:server"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 16.1",
                "product": {
                  "name": "SUSE Linux Enterprise Server 16.1",
                  "product_id": "SUSE Linux Enterprise Server 16.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.1:server"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP applications 16.0",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP applications 16.0",
                  "product_id": "SUSE Linux Enterprise Server for SAP applications 16.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.0:server-sap"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "openSUSE Tumbleweed",
                "product": {
                  "name": "openSUSE Tumbleweed",
                  "product_id": "openSUSE Tumbleweed",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:opensuse:tumbleweed"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "govulncheck-vulndb-0.0.20241213T205935-1.1",
                "product": {
                  "name": "govulncheck-vulndb-0.0.20241213T205935-1.1",
                  "product_id": "govulncheck-vulndb-0.0.20241213T205935-1.1",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/govulncheck-vulndb@0.0.20241213T205935-1.1?upstream=govulncheck-vulndb-0.0.20241213T205935-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
                "product": {
                  "name": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
                  "product_id": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/govulncheck-vulndb@0.0.20250814T182633-160000.1.2?upstream=govulncheck-vulndb-0.0.20250814T182633-160000.1.2.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "govulncheck-vulndb-0.0.20250814T182633-160099.2.2",
                "product": {
                  "name": "govulncheck-vulndb-0.0.20250814T182633-160099.2.2",
                  "product_id": "govulncheck-vulndb-0.0.20250814T182633-160099.2.2",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/govulncheck-vulndb@0.0.20250814T182633-160099.2.2?upstream=govulncheck-vulndb-0.0.20250814T182633-160099.2.2.src.rpm"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2 as component of SUSE Linux Enterprise Server 16.0",
          "product_id": "SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2"
        },
        "product_reference": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "govulncheck-vulndb-0.0.20250814T182633-160099.2.2 as component of SUSE Linux Enterprise Server 16.1",
          "product_id": "SUSE Linux Enterprise Server 16.1:govulncheck-vulndb-0.0.20250814T182633-160099.2.2"
        },
        "product_reference": "govulncheck-vulndb-0.0.20250814T182633-160099.2.2",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 16.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2 as component of SUSE Linux Enterprise Server for SAP applications 16.0",
          "product_id": "SUSE Linux Enterprise Server for SAP applications 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2"
        },
        "product_reference": "govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP applications 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "govulncheck-vulndb-0.0.20241213T205935-1.1 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:govulncheck-vulndb-0.0.20241213T205935-1.1"
        },
        "product_reference": "govulncheck-vulndb-0.0.20241213T205935-1.1",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-37032",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2024-37032"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
          "SUSE Linux Enterprise Server 16.1:govulncheck-vulndb-0.0.20250814T182633-160099.2.2",
          "SUSE Linux Enterprise Server for SAP applications 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
          "openSUSE Tumbleweed:govulncheck-vulndb-0.0.20241213T205935-1.1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2024-37032",
          "url": "https://www.suse.com/security/cve/CVE-2024-37032"
        },
        {
          "category": "external",
          "summary": "SUSE Security Ratings",
          "url": "https://www.suse.com/support/security/rating/"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1225724 for CVE-2024-37032",
          "url": "https://bugzilla.suse.com/1225724"
        },
        {
          "category": "external",
          "summary": "Advisory link for openSUSE-SU-2024:14599-1",
          "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QTUY324RV3FFZBHVIWDHRCIOPJHIJIN4/"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
            "SUSE Linux Enterprise Server 16.1:govulncheck-vulndb-0.0.20250814T182633-160099.2.2",
            "SUSE Linux Enterprise Server for SAP applications 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2",
            "openSUSE Tumbleweed:govulncheck-vulndb-0.0.20241213T205935-1.1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2024-05-31T06:00:01Z",
          "details": "important"
        }
      ],
      "title": "CVE-2024-37032"
    }
  ]
}
Enrichment data
View JSON API Download JSON