The Apache HTTP Server did not verify that a process was an Apache child
process before sending it signals. A local attacker who has the ability to
run scripts on the Apache HTTP Server could manipulate the scoreboard and
cause arbitrary processes to be terminated, which could lead to a denial of
service. (CVE-2007-3304)
A flaw was found in the Apache HTTP Server mod_status module. Sites with
the server-status page publicly accessible and ExtendedStatus enabled were
vulnerable to a cross-site scripting attack. On Red Hat Enterprise Linux
the server-status page is not enabled by default and it is best practice to
not make this publicly available. (CVE-2006-5752)
Posted Feb 21, 2008 22:26 UTC (Thu) by kmccarty (subscriber, #12085)
[Link]
FYI, these were fixed in the latest Debian "Etch" release, 4.0r3, in apache version 1.3.34-4.1+etch1. For some reason it was not deemed necessary to issue a Debian Security Advisory, but people with the usual lines in their sources.list should get the update automatically on their next APT update and upgrade.