DoS (bandwidth consumption) via a Range header specifying multiple
copies of the same fragment over a TCP connection with a large window
size. The severity is explicitly disputed by third parties (NVD carries
the "disputed" tag) because the large TCP window size the attack relies
on is not normally supported or configured by the server, and the same
effect is achievable by simply downloading the file. Red Hat states it
"does not consider this issue to be a security vulnerability". Debian
classifies it as an unimportant issue. No code change required in the
shipped 2.4.68 build.
https://security-tracker.debian.org/tracker/CVE-2007-0086