Summary
The remote host is missing updates announced in
advisory GLSA 200407-18.
Solution
All mod_ssl users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=net-www/mod_ssl-2.8.19'
# emerge '>=net-www/mod_ssl-2.8.19'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200407-18 http://bugs.gentoo.org/show_bug.cgi?id=57379
http://marc.theaimsgroup.com/?l=apache-modssl&m=109001100906749&w=2
Insight
A bug in mod_ssl may allow a remote attacker to execute arbitrary code when Apache is configured to use mod_ssl and mod_proxy.