This security vulnerability only exists in the CVS server. CVS client builds are not affected.

A corrected link to the NEWS file for this release: <http://ccvs.cvshome.org/source/browse/ccvs/NEWS?rev=1.112.2.1&content-type=text/x-cvsweb-markup>

Derek

Derek Robert Price wrote:

CVS 1.11.5 has been released. This release fixes a major security vulnerability in CVS. The Common Vulnerabilities and Exposures project (cve.mitre.org <http://cve.mitre.org>) has assigned the name CAN-2003-0015 to this issue. See the text of CAN-2003-0015 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0015> for more information.

You may also take a look at the NEWS file <http://ccvs.cvshome.org/source/browse/ccvs/NEWS?rev=1.112&content-type=text/x-cvsweb-markup> from the source distribution or go directly to the downloads page <http://ccvs.cvshome.org/servlets/ProjectDownloadList>.

Thanks go to Stefan Esser <http:[EMAIL PROTECTED]> for his help on this issue!

Derek


_______________________________________________
Info-cvs mailing list
[EMAIL PROTECTED]
http://mail.gnu.org/mailman/listinfo/info-cvs

Reply via email to