Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.
https://exchange.xforce.ibmcloud.com/vulnerabilities/11125
https://exchange.xforce.ibmcloud.com/vulnerabilities/11124
http://www.securityfocus.com/bid/6659
http://www.kb.cert.org/vuls/id/979793
http://www.kb.cert.org/vuls/id/825177
http://www.apacheweek.com/issues/03-01-24#security
http://marc.info/?l=apache-httpd-announce&m=104313442901017&w=2