A flaw was found in the httpd modperl Apache::Status module. If a site has the non default setting of making /perl-status page accessible, remote attackers could use that flaw to trick users or steal sensitive browser data.
The original public announcement can be found here: http://marc.info/?l=apache-modperl&m=123862312808765&w=2
The CVE id mentioned in the above mail is wrong, CVE-2009-0796 is the proper CVE id.