You make it sound like the version in Sarge has these security vulnerabilities fixed. Except, it's still 4.3.9 - instead of 4.3.10 which is supposed to fix this problem.
4.3.10 is already in Sarge. (See http://packages.qa.debian.org/php4)
Regards, Philipp Kern
-- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]