[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CVS Update: src



CVSROOT:	/cvs
Module name:	src
Repository:	src/gnu/usr.bin/cvs/src/
Changes by:	odin@akbar.cleannorth.org.	04/05/24 18:43:36

Modified files:
	src/gnu/usr.bin/cvs/src/: client.c modules.c 

Log message:
	From OPENBSD_3_5
	
	MFC:
	Fix by otto@
	
	- a malicious server may send path names that translate out of the
	local cvs tree on the client, enabling the server to overwrite files
	on the client.
	
	- a client may read files outside the repository using the -p flag
	with the checkout command.
	
	ok deraadt@ otto@


Main Menu:

Site Tools:


Here, spammer, have some addresses.