CVE-2015-8980: Fedoraproject Fedora
Critical severity, CVSS 9.8. EPSS: 6.7% chance of exploitation in the next 30 days.
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
Affected products
- Fedoraproject Fedora: version 24 only
- Opensuse Leap: version 42.1 only; version 42.2 only
- PHP-Gettext Project PHP-Gettext: before 1.0.12 (fixed in 1.0.12)
- Red Hat Enterprise Linux: version 5.0 only
Published 2019-11-04. Last modified 2026-06-17.