Critical severity9.8NVD Advisory· Published Nov 4, 2019· Updated Jun 17, 2026
CVE-2015-8980
CVE-2015-8980
Description
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:php-gettext_project:php-gettext:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:php-gettext_project:php-gettext:*:*:*:*:*:*:*:*range: <1.0.12
- (no CPE)range: <1.0.12
- cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
- php-gettext/php-gettextdescription
Patches
Vulnerability mechanics
References
7- seclists.org/fulldisclosure/2016/Aug/76nvdExploitMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-updates/2017-02/msg00015.htmlnvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2017/01/18/4nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/95754nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- launchpad.net/php-gettext/trunk/1.0.12nvdRelease NotesThird Party Advisory
- lwn.net/Alerts/708838/nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.