This issue was reported to bugtraq on 2004-09-15 http://www.securityfocus.com/archive/1/375370 Bad array parsing in the rfc1867.c file could lead to the overwriting of the $_FILES array, which in turn could allow an attacker to write arbitrary files with the permission of the user running apache.
I've created attachment 104908 [details] which contains the upstream patch from CVS. We could also upgrade to version 4.3.9 which fixes this issue.
http://www.redhat.com/archives/fedora-announce-list/2004-December/msg00092.html