A buffer "over-read" flaw was found in Apache httpd used for caching. This allows a malicious origin server to possibly cause a process crash on a caching forward proxy, which is a DoS for a threaded MPM on httpd 2.0+ On httpd 1.3 this would cause a client crash but this is not considered a security issue as httpd would continue to run and spawn new children as required. http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2
This issue has been addressed in following products: Red Hat Certificate System 7.3 Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html