Actually, I may be wrong with my above post. I just re-read the CVE reports again and can't work out if the Apache version involved ignores that directive totally from the main httpd.conf, so that the whole file system is open?

Ideas anyone?

