Ubuntu Security Notice USN-791-3 – It was discovered that Smarty did not correctly filter certain math inputs. A remote attacker using Smarty via a web service could exploit this to execute subsets of shell commands as the web server user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78632/USN-791-3.txt
Source: https://packetstormsecurity.com/files/78632/Ubuntu-Security-Notice-791-3.html

