The streamreqbodycl function in modproxyhttp.c in the modproxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
François Guerraz reported in Debian BTS a possible DoS (CPU consumption) a DoS with moddeflate since it does not stop to compress large files even after the network connection has been closed. This allows to use large amounts of CPU if there is a largish file available that has moddeflate enabled.
Original report: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712
Post to the apache-httpd-dev mailing list: http://marc.info/?l=apache-httpd-dev&m=124621326524824&w=2