Untriaged
The plural form formula in ngettext family of calls in …
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
References
- 95754 vdb-entry x_refsource_BID
- openSUSE-SU-2017:0372 vendor-advisory x_refsource_SUSE
- [oss-security] 20170118 Re: CVE Request: php-gettext: Arbitrary code execution in select_string, ngettext and npgettext count parameter mailing-list x_refsource_MLIST
- https://bugzilla.redhat.com/show_bug.cgi?id=1367462 x_refsource_CONFIRM
- https://lwn.net/Alerts/708838/ x_refsource_CONFIRM
- [Full Disclosure] 20160815 php-gettext php code execution in select_string, ngettext, npgettext count parameter <1.0.12 mailing-list x_refsource_MLIST
- https://launchpad.net/php-gettext/trunk/1.0.12 x_refsource_CONFIRM
- 95754 vdb-entry x_refsource_BID x_transferred
- openSUSE-SU-2017:0372 vendor-advisory x_refsource_SUSE x_transferred
- [oss-security] 20170118 Re: CVE Request: php-gettext: Arbitrary code execution in select_string, ngettext and npgettext count parameter mailing-list x_refsource_MLIST x_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=1367462 x_refsource_CONFIRM x_transferred
- https://lwn.net/Alerts/708838/ x_refsource_CONFIRM x_transferred
- [Full Disclosure] 20160815 php-gettext php code execution in select_string, ngettext, npgettext count parameter <1.0.12 mailing-list x_refsource_MLIST x_transferred
- https://launchpad.net/php-gettext/trunk/1.0.12 x_refsource_CONFIRM x_transferred
- 95754 vdb-entry x_refsource_BID
- openSUSE-SU-2017:0372 vendor-advisory x_refsource_SUSE
- [oss-security] 20170118 Re: CVE Request: php-gettext: Arbitrary code execution in select_string, ngettext and npgettext count parameter mailing-list x_refsource_MLIST
- https://bugzilla.redhat.com/show_bug.cgi?id=1367462 x_refsource_CONFIRM
- https://lwn.net/Alerts/708838/ x_refsource_CONFIRM
- [Full Disclosure] 20160815 php-gettext php code execution in select_string, ngettext, npgettext count parameter <1.0.12 mailing-list x_refsource_MLIST
- https://launchpad.net/php-gettext/trunk/1.0.12 x_refsource_CONFIRM
- 95754 vdb-entry x_refsource_BID x_transferred
- openSUSE-SU-2017:0372 vendor-advisory x_refsource_SUSE x_transferred
- [oss-security] 20170118 Re: CVE Request: php-gettext: Arbitrary code execution in select_string, ngettext and npgettext count parameter mailing-list x_refsource_MLIST x_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=1367462 x_refsource_CONFIRM x_transferred
- https://lwn.net/Alerts/708838/ x_refsource_CONFIRM x_transferred
- [Full Disclosure] 20160815 php-gettext php code execution in select_string, ngettext, npgettext count parameter <1.0.12 mailing-list x_refsource_MLIST x_transferred
- https://launchpad.net/php-gettext/trunk/1.0.12 x_refsource_CONFIRM x_transferred
Affected products
php-gettext
- ==before 1.0.12
Matching in nixpkgs
pkgs.phpExtensions.gettext
PHP upstream extension: gettext
pkgs.php81Extensions.gettext
PHP upstream extension: gettext
pkgs.php82Extensions.gettext
PHP upstream extension: gettext
pkgs.php83Extensions.gettext
PHP upstream extension: gettext
pkgs.php84Extensions.gettext
PHP upstream extension: gettext
Package maintainers
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@piotrkwiecinski Piotr Kwiecinski <piokwiecinski+nixpkgs@gmail.com>
-
@aanderse Aaron Andersen <aaron@fosslib.net>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>