Candidate: CVE-2011-3740 PublicDate: 2011-09-23 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3740 Description: FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files. Ubuntu-Description: Notes: tyhicks> Setting affected package to libfpdi-php rather than frontaccounting tyhicks> since the file mentioned in the CVE description is owned by tyhicks> libfpdi-php. Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_libfpdi-php: upstream_libfpdi-php: needed hardy_libfpdi-php: DNE lucid_libfpdi-php: DNE maverick_libfpdi-php: DNE natty_libfpdi-php: DNE oneiric_libfpdi-php: ignored (reached end-of-life) precise_libfpdi-php: ignored (reached end-of-life) precise/esm_libfpdi-php: DNE (precise was needed) quantal_libfpdi-php: ignored (reached end-of-life) raring_libfpdi-php: ignored (reached end-of-life) saucy_libfpdi-php: ignored (reached end-of-life) trusty_libfpdi-php: ignored (reached end-of-life) trusty/esm_libfpdi-php: DNE (trusty was needed) utopic_libfpdi-php: ignored (reached end-of-life) vivid_libfpdi-php: ignored (reached end-of-life) vivid/stable-phone-overlay_libfpdi-php: DNE vivid/ubuntu-core_libfpdi-php: DNE wily_libfpdi-php: ignored (reached end-of-life) xenial_libfpdi-php: ignored (end of standard support, was needed) yakkety_libfpdi-php: ignored (reached end-of-life) zesty_libfpdi-php: DNE artful_libfpdi-php: DNE bionic_libfpdi-php: DNE cosmic_libfpdi-php: DNE disco_libfpdi-php: DNE eoan_libfpdi-php: DNE focal_libfpdi-php: DNE groovy_libfpdi-php: DNE hirsute_libfpdi-php: DNE impish_libfpdi-php: DNE jammy_libfpdi-php: DNE devel_libfpdi-php: DNE