Ubuntu Security Notice 485-1 – It was discovered that the PHP xmlrpc extension did not correctly check heap memory allocation sizes. A remote attacker could send a specially crafted request to a PHP application using xmlrpc and execute arbitrary code as the Apache user. Stefan Esser discovered a flaw in the random number initialization of the PHP SOAP extension. This could lead to remote attackers being able to predict certain elements of the authentication mechanism.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57805/USN-485-1.txt
Source: https://packetstormsecurity.com/files/57805/Ubuntu-Security-Notice-485-1.html