The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.
https://exchange.xforce.ibmcloud.com/vulnerabilities/12091
http://www.securityfocus.com/bid/7725
http://www.redhat.com/support/errata/RHSA-2003-186.html
http://www.kb.cert.org/vuls/id/479268
http://www.apache.org/dist/httpd/Announcement2.html
http://secunia.com/advisories/8881
http://marc.info/?l=bugtraq&m=105418115512559&w=2
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000661