===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata.html,v
retrieving revision 1.485
retrieving revision 1.486
diff -u -r1.485 -r1.486
--- www/errata.html 2004/05/04 15:44:39 1.485
+++ www/errata.html 2004/05/05 07:35:15 1.486
@@ -56,7 +56,19 @@
All architectures
-- No problems identified yet.
+
-
+002: SECURITY FIX: May 5,
+2004
+Pathname validation problems have been found in
+cvs(1),
+allowing malicious clients to create files outside the repository, allowing
+malicious servers to overwrite files outside the local CVS tree on
+the client and allowing clients to check out files outside the CVS
+repository.
+
+
+A source code patch exists which remedies this problem.
+
@@ -168,7 +180,7 @@
www@openbsd.org
-
$OpenBSD: errata.html,v 1.485 2004/05/04 15:44:39 deraadt Exp $
+
$OpenBSD: errata.html,v 1.486 2004/05/05 07:35:15 otto Exp $