Hello Stephen, I sent a suitable security-package with basically the same patch in it to the team in November 2005, immediately got a "nice, will do this later today" and nothing ever happened. Maybe it's because the patch potentially breaks logs of some servers using the lib, or because it's in question, if the hole is even exploitable. Well, zobel asked for the package now, I guess he will take care of it.
Carsten -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]