Debian Security Advisory DSA 803-1 (apache)

Summary
The remote host is missing an update to apache announced via advisory DSA 803-1. A vulnerability has been discovered in the Apache web server. When it is acting as an HTTP proxy, it allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct cross-site scripting attacks, which causes Apache to incorrectly handle and forward the body of the request. For the old stable distribution (woody) this problem has been fixed in version 1.3.26-0woody7.
Solution
For the stable distribution (sarge) this problem has been fixed in version 1.3.33-6sarge1. For the unstable distribution (sid) this problem has been fixed in version 1.3.33-8. We recommend that you upgrade your Apache package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20803-1