This issue was reported to bugtraq on 2004-09-15. http://www.securityfocus.com/archive/1/375294 Bad array parsing in php_variables.c could lead to show arbitrary memory content such as pieces of php code and other data. This affects all GET, POST or COOKIES variables.
I've created attachment 104909 [details] which is what's in the upstream CVS to fix this issue. We can also upgrade to version 4.3.9 which fixes this issue.
http://bugs.php.net/?id=30442 looks like a similar bug is still present even in 4.3.9, yuck :(
http://www.redhat.com/archives/fedora-announce-list/2004-December/msg00092.html