{"id":"CVE-2021-39158","details":"NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to install it within NVCaffe.","aliases":["GHSA-fmpp-8pwg-vwh9"],"modified":"2026-07-09T12:20:37.199509Z","published":"2021-08-23T21:15:09.643Z","references":[{"type":"ADVISORY","url":"https://github.com/NVIDIA/caffe/security/advisories/GHSA-fmpp-8pwg-vwh9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nvidia/caffe","events":[{"introduced":"0"},{"fixed":"21fae6992de15a5dea6e04044b8188360c09a2b8"}],"database_specific":{"cpe":"cpe:2.3:a:nvidia:nvcaffe:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.17.4"}],"source":"CPE_RANGE"}}],"versions":["v0.17.3","v0.17.2","v0.17.1","v0.17.0","v0.16.6","v0.16.5","v0.16.4","v0.16.3","v0.16.2","v0.15.14","v0.15.13","v0.15.12","v0.15.11","v0.15.10","v0.15.9","v0.15.8","v0.15.7","v0.15.6","v0.15.5","v0.15.4","v0.15.3","v0.15.2","v0.14-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39158.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}