rPath Security Advisory: 2006-0122-2 - Previous versions of the kernel package have two specific vulnerabilities that are addressed in this version.
e8c7f28067e9cd6a01b4845a2aabd4bb9cbf7f85b3ebf57cd0d6eaa0005b3744
In previous kernel 2.6 versions, systems that use the SCTP protocol are vulnerable to remote denial of service attacks including remotely-triggered kernel crashes, and all systems are vulnerable to local denial of service including locally-triggered kernel hangs.
0a184d8c9cd14cdfc29f7f2d78a66c38915f67721aee3a75be265bfc14048501
rPath Security Advisory: 2006-0082-1: In previous versions of the vixie-cron package, when the /etc/security/limits.conf file has been set up with limits for any user, and that user has permission to use the cron facility, that user can use vixie-cron to run arbitrary programs as root by exceeding the limits set in /etc/security/limits.conf.
dcb6a72ad24369cff4454324fccd875aa7a0ddda3c1a9efdcda0877f90da49e8