Debian Security Advisory

DLA-1056-1 cvs -- LTS security update

Date Reported:
13 Aug 2017
Affected Packages:
cvs
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-12836.
More information:

It was discovered that there was a command injection vulnerability in the CVS revision control system.

For Debian 7 Wheezy, this issue has been fixed in cvs version 2:1.12.13+real-9+deb7u1.

We recommend that you upgrade your cvs packages. Thanks to Thorsten Glaser <tg@mirbsd.de> for preparing and testing this upload.