PatchSiren cyber security CVE debrief
CVE-2016-6175 PHP Gettext Project CVE debrief
CVE-2016-6175 is a critical remote code execution issue in php-gettext 1.0.12 and earlier. The flaw is an eval injection condition tied to a crafted plural forms header, which can allow arbitrary PHP code execution with no user interaction. NVD rates the issue CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and maps it to CWE-94.
- Vendor
- PHP Gettext Project
- Product
- PHP-Gettext
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-07
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-07
- Advisory updated
- 2026-05-13
Who should care
Teams running php-gettext 1.0.12 or earlier, and maintainers of applications that bundle or vendor that library. Web application owners should treat this as urgent because successful exploitation can fully compromise the PHP process and the host application.
Technical summary
The vulnerable component is php-gettext, with NVD listing affected versions up to and including 1.0.12. The weakness is classified as CWE-94 (code injection) and is described as an eval injection issue triggered by a crafted plural forms header. Based on the supplied NVD data, the impact is remote, requires no privileges or user interaction, and can result in full confidentiality, integrity, and availability compromise.
Defensive priority
Critical priority. The combination of network exposure, no authentication, no user interaction, and remote code execution warrants immediate remediation.
Recommended defensive actions
- Inventory all applications, libraries, and containers that include php-gettext.
- Upgrade php-gettext to a version newer than 1.0.12 as soon as possible.
- If immediate upgrading is not possible, isolate affected systems and reduce exposure of any code paths that process untrusted translation files or headers.
- Rebuild and redeploy any packaged applications that vendor the vulnerable library so the fix is actually present in production.
- Verify remediation by checking the deployed php-gettext version and confirming the affected code path is no longer present.
Evidence notes
Supplied NVD data identifies php-gettext_project versions through 1.0.12 as vulnerable, assigns CVSS 3.0 9.8, and maps the issue to CWE-94. The description states that a crafted plural forms header can lead to arbitrary PHP code execution. NVD also lists related references to a Launchpad bug, a GitHub commit, a blog advisory, and an Exploit-DB entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6175 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6175
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6175 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6175
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://bugs.launchpad.net/php-gettext/+bug/1606184
-
Source reference
Unverified legacy reference
URL: https://github.com/NagVis/nagvis/commit/4fe8672a5aec3467da72b5852ca6d283c15adb53
-
Source reference
Unverified legacy reference
URL: https://kmkz-web-blog.blogspot.cz/2016/07/advisory-cve-2016-6175.html
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/40154/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.