Providing an initial key with no '=' assignment could reflect the stale value
of uninitialized pool memory used by the prior request leading to leakage of
potentially confidential information and a segfault.
For Debian 7 "Wheezy", this issue has been fixed in apache2 version
2.2.22-13+deb7u10.
We recommend that you upgrade your apache2 packages.
Regards,
- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-
Get the latest Linux and open source security news straight to your inbox.