Multiple stack-based buffer overflows in (1) modalias and (2) modrewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.