Vulnerability Bulletins

DSA-3940 cvs - security update

   
Affected software Debian
 
It was discovered that CVS, a centralised version control system, didnot correctly handle maliciously constructed repository URLs, whichallowed an attacker to run an arbitrary shell command.

More info:

https://www.debian.org/security/2017/dsa-3940