Updated spamassassin packages that fix a security issue are now available
for CentOS Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
SpamAssassin provides a way to reduce unsolicited commercial email (spam)
from incoming email.
A flaw was found in the way SpamAssassin processes HTML email containing
URIs. A carefully crafted mail message could cause SpamAssassin to consume
significant resources. If a number of these messages are sent, this could
lead to a denial of service, potentially delaying or preventing the
delivery of email. (CVE-2007-0451)
Users of SpamAssassin should upgrade to these updated packages which
contain version 3.1.8 which is not vulnerable to these issues.