Stable CVS releases up to 1.11.15 and CVS feature releases up to 1.12.7 both contain a flaw when deciding if a CVS entry line should get a modified or unchanged flag attached. This results in a heap overflow which can be exploited to execute arbitrary code on the CVS server. This could allow a repository compromise.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/33370/072004.txt
Source: https://packetstormsecurity.com/files/33370/072004.txt.html