Apache 1.3.27 is out to fix 3 security vulnerabilities in 1.3.26 and below. Are fixed pacakges on their way to security.debian.org? Did ASF notify any vendors in advance of their announcement today?
http://www.apache.org/dist/httpd/Announcement.html -- Paul Baker "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." -- Benjamin Franklin, 1759 GPG Key: http://homepage.mac.com/pauljbaker/public.asc -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]