On Sun, 15 Sep 2002, Mark Berkwitt wrote: > Thanks for the leads. > I did a full update using up2date and selecting all updates offered. > Currently I have > apache-1.3.23-14 and mod_ssl-2.8.7-6 > running. Are they too old? That's fine. RedHat usually back-ports security patches to avoid introducing too many software changes. For example, your version of Apache should have the vulnerability patched that the Apache group fixed in version 1.3.26. ~M