iDEFENSE reports that a format string vulnerability in mod_auth_pgsql, a library used to authenticate web users against a PostgreSQL database, could be used to execute arbitrary code with the privileges of the httpd user.
The old stable distribution (woody) does not contain libapache2-mod-auth-pgsql.
For the stable distribution (sarge) this problem has been fixed in version 2.0.2b1-5sarge0.
For the unstable distribution (sid) this problem will be fixed shortly.
We recommend that you upgrade your libapache2-mod-auth-pgsql package.
MD5 checksums of the listed files are available in the original advisory.