Skip to content

gfortran pip dependency

Low
drnikolaev published GHSA-fmpp-8pwg-vwh9 Aug 23, 2021

Package

pip gfortran (pip)

Affected versions

<0.17.4

Patched versions

0.17.4

Description

NVCaffe's python required dependencies list used to contain gfortranversion prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to install it within NVCaffe.

NVIDA thanks Tencent Force for reporting the issue.

Severity

Low

CVE ID

CVE-2021-39158

Weaknesses

No CWEs