Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
http://www.securityfocus.com/bid/5033
http://www.securityfocus.com/bid/20005
http://www.redhat.com/support/errata/RHSA-2003-106.html
http://www.redhat.com/support/errata/RHSA-2002-150.html
http://www.redhat.com/support/errata/RHSA-2002-126.html
http://www.linuxsecurity.com/advisories/other_advisory-2137.html
http://www.kb.cert.org/vuls/id/944335
http://www.frsirt.com/english/advisories/2006/3598
http://www.debian.org/security/2002/dsa-133
http://www.debian.org/security/2002/dsa-132
http://www.debian.org/security/2002/dsa-131
http://www.cert.org/advisories/CA-2002-17.html