According to this Apache httpd commit:
+ *) Add explicit charset to the output of various modules to work around
+ possible cross-site scripting flaws affecting web browsers that do not
+ derive the response character set as required by RFC2616. One of these
+ reported by SecurityReason [Joe Orton]
Only mod_proxy_ftp seems to have security implications.
httpd-2.2.8-1.fc8 has been submitted as an update for Fedora 8
httpd-2.2.8-1.fc7 has been submitted as an update for Fedora 7
httpd-2.2.8-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
httpd-2.2.8-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products:
Red Hat Certificate System 7.3
Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html