DragonFly BSD
DragonFly kernel List (threaded) for 2004-01
Re: HEADS UP: CVS import

From: Jeroen Ruigrok/asmodai <asmodai@xxxxxx>
Date: Mon, 19 Jan 2004 14:01:52 +0100

This release (1.11.11) has some security fixes, to know:

Stable CVS 1.11.11 has been released. Stable releases contain only bug
fixes from previous versions of CVS. This release adds code to the CVS
server to prevent it from continuing as root after a user login, as an
extra failsafe against a compromise of the CVSROOT/passwd file.
Previously, any user with the ability to write the CVSROOT/passwd file
could execute arbitrary code as the root user on systems with CVS
pserver access enabled. We recommend this upgrade for all CVS servers!

