CVE-2011-3707
Publication date 23 September 2011
Last updated 24 July 2024
Ubuntu priority
Description
JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Auth/Yadis/Yadis.php and certain other files.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| php-openid | 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Ignored see notes | |
| 14.04 LTS trusty | Not in release | |