===================================================================
RCS file: /cvsrepo/anoncvs/cvs/www/errata34.html,v
retrieving revision 1.3
retrieving revision 1.4
diff -u -r1.3 -r1.4
--- www/errata34.html 2004/03/30 06:36:36 1.3
+++ www/errata34.html 2004/05/05 07:35:16 1.4
@@ -56,6 +56,19 @@
All architectures
+-
+017: SECURITY FIX: May 5,
+2004
+Pathname validation problems have been found in
+cvs(1),
+allowing malicious clients to create files outside the repository, allowing
+malicious servers to overwrite files outside the local CVS tree on
+the client and allowing clients to check out files outside the CVS
+repository.
+
+
+A source code patch exists which remedies this problem.
+
-
016: RELIABILITY FIX: March 17,
2004
@@ -305,7 +318,7 @@
www@openbsd.org
-
$OpenBSD: errata34.html,v 1.3 2004/03/30 06:36:36 david Exp $
+
$OpenBSD: errata34.html,v 1.4 2004/05/05 07:35:16 otto Exp $