cvs (2:1.12.13+real-6ubuntu0.1) oneiric-security; urgency=low

  * SECURITY UPDATE: arbitrary code execution via heap overflow
    - src/client.c: remove use of write_buf. Patch thanks to Petr Pisar.
    - CVE-2012-0804
 -- Marc Deslauriers <email address hidden>   Mon, 13 Feb 2012 10:37:01 -0500

Marc Deslauriers on 2012-02-13
Ubuntu Developers
Oneiric updates on 2012-02-22 main vcs
Oneiric security on 2012-02-22 main vcs


File Size MD5 Checksum
cvs_1.12.13+real.orig.tar.gz 4.5 MiB 7a71a2e7a64973ecf255965956a1d338
cvs_1.12.13+real-6ubuntu0.1.diff.gz 85.0 KiB 629b229253e643cfcdd10e54a0c86935
cvs_1.12.13+real-6ubuntu0.1.dsc 2.0 KiB c10a54e148f9794806e8deb63e3d1167

cvs: Concurrent Versions System

 CVS is a version control system, which allows you to keep access
 to old versions of files (usually source code), keep a log of
 who, when, and why changes occurred, etc., like RCS or SCCS.
 It handles multiple developers, multiple directories, triggers to
 enable/log/control various operations, and can work over a wide
 area network. The texinfo manual provides further information on
 more tasks that it can perform.
 There are some tasks that are not covered by CVS. They can be done in
 conjunction with CVS but will tend to require some script-writing and
 software other than CVS. These tasks are bug-tracking, build management
 (that is, make and make-like tools), and automated testing. However,
 CVS makes these tasks easier.
 This package contains a CVS binary which can act as both client and
 server, although there is no CVS dæmon; to access remote repositories,
 please use :extssh: not :pserver: any more.