> To start, you can get information on apache 1.3 security vulnerabilities > here: > http://httpd.apache.org/security/vulnerabilities_13.html > You'll notice this lines up quite closely with the list you quote. > All of these problems could be fixed simply by upgrading your server > to the most recent 1.3 release: 1.3.33. 1.3.34 was released several weeks ago (at least the Unix version, did William Rowe upload the win32 1.3.34 binary yet?) Joost --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx