There's also Arstechnica article: https://arstechnica.com/information-technology/2017/09/apach...
Tracking fix publishing:
* Debian: https://security-tracker.debian.org/tracker/CVE-2017-9798
* Ubuntu: https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2...
* Red Hat: https://access.redhat.com/security/cve/CVE-2017-9798 and https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-9798