PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6175 PHP Gettext Project CVE debrief

CVE-2016-6175 is a critical remote code execution issue in php-gettext 1.0.12 and earlier. The flaw is an eval injection condition tied to a crafted plural forms header, which can allow arbitrary PHP code execution with no user interaction. NVD rates the issue CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and maps it to CWE-94.

Vendor
PHP Gettext Project
Product
PHP-Gettext
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-07
Original CVE updated
2026-05-13
Advisory published
2017-02-07
Advisory updated
2026-05-13

Who should care

Teams running php-gettext 1.0.12 or earlier, and maintainers of applications that bundle or vendor that library. Web application owners should treat this as urgent because successful exploitation can fully compromise the PHP process and the host application.

Technical summary

The vulnerable component is php-gettext, with NVD listing affected versions up to and including 1.0.12. The weakness is classified as CWE-94 (code injection) and is described as an eval injection issue triggered by a crafted plural forms header. Based on the supplied NVD data, the impact is remote, requires no privileges or user interaction, and can result in full confidentiality, integrity, and availability compromise.

Defensive priority

Critical priority. The combination of network exposure, no authentication, no user interaction, and remote code execution warrants immediate remediation.

Recommended defensive actions

  • Inventory all applications, libraries, and containers that include php-gettext.
  • Upgrade php-gettext to a version newer than 1.0.12 as soon as possible.
  • If immediate upgrading is not possible, isolate affected systems and reduce exposure of any code paths that process untrusted translation files or headers.
  • Rebuild and redeploy any packaged applications that vendor the vulnerable library so the fix is actually present in production.
  • Verify remediation by checking the deployed php-gettext version and confirming the affected code path is no longer present.

Evidence notes

Supplied NVD data identifies php-gettext_project versions through 1.0.12 as vulnerable, assigns CVSS 3.0 9.8, and maps the issue to CWE-94. The description states that a crafted plural forms header can lead to arbitrary PHP code execution. NVD also lists related references to a Launchpad bug, a GitHub commit, a blog advisory, and an Exploit-DB entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6175 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6175

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6175 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6175

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.