Ubuntu Security Notice 321-1 – Jean-David Maillefer discovered a format string bug in the date_format() function’s error reporting. By calling the function with invalid arguments, an authenticated user could exploit this to crash the server.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/48463/USN-321-1.txt
Source: https://packetstormsecurity.com/files/48463/Ubuntu-Security-Notice-321-1.html