IOActive has discovered a buffer overflow in the Host Header field in the legacy version of the mod_jk2 Apache module (jakarta-tomcat-connectors) which allows for remote code execution in the context of the Apache process.

http://www.securiteam.com/unixfocus/5QP0J0UNFI.html