From: GP lisper
Subject: ALERT:  Apache proxy users
Date: 
Message-ID: <1126232642.040ef04ee3d784c7acbc0ff233accea7@teranews>
From Bugtraq:

- --------------------------------------------------------------------------
Debian Security Advisory DSA 803-1                     ········@debian.org
http://www.debian.org/security/                             Martin Schulze
September 8th, 2005                     http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : apache
Vulnerability  : programming error
Problem type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2088
Debian Bug     : 322607

A vulnerability has been discovered in the Apache web server.  When it
is acting as an HTTP proxy, it allows remote attackers to poison the
web cache, bypass web application firewall protection, and conduct
cross-site scripting attacks, which causes Apache to incorrectly
handle and forward the body of the request.

For the old stable distribution (woody) this problem has been fixed in
version 1.3.26-0woody7.

For the stable distribution (sarge) this problem has been fixed in
version 1.3.33-6sarge1.

For the unstable distribution (sid) this problem has been fixed in
version 1.3.33-8.

We recommend that you upgrade your Apache package.


-- 
You can always tell a really good idea by the enemies it makes.