Package xmlrpc-c-ss-1.16.42 has a denial-of-service vulnerability. It is also four years old. Is there any reason we don't upgrade it to 1.32? -- D'Arcy J.M. Cain <darcy%NetBSD.org@localhost> http://www.NetBSD.org/ IM:darcy%Vex.Net@localhost