Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17384
http://www.trustix.org/errata/2004/0047/
http://www.redhat.com/support/errata/RHSA-2004-463.html
http://www.novell.com/linux/security/advisories/2004_32_apache2.html
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096