Reported against the mod_php module for Apache 2.0.x, allowing local
users with write access to PHP scripts to signal the server process
group and reuse its file descriptors. The PHP developers disputed the
report ("The opened file descriptors are opened by Apache. It is the job
of Apache to protect them ... Not a bug in PHP"), and Red Hat states it
"is not a vulnerability" since mod_php runs with the privileges of the
httpd child by design. NVD carries the "disputed" tag. mod_php is not
shipped by the apache2 source package and is not used in these images.
https://security-tracker.debian.org/tracker/CVE-2003-1307