This tracks issues solved by the proposed spamassassin-3.0.x for RHEL4U.
http://wiki.apache.org/spamassassin/changes302 http://wiki.apache.org/spamassassin/changes303 All changes in the 3.0.x branch are double-reviewed upstream and limited to bug fixes. Zero risk and well tested while maintaining ABI with 3rd party plugins. Bug #156390 prevents OOM conditions which can DoS the entire machine.
Fixed in RHSA-2005:498 spamassassin-3.0.4-1.el4