OpenPKG Security Advisory OpenPKG-SA-2006.014 – Brian Caswell from Sourcefire discovered vulnerabilities in OSSP Shiela, a CVS repository access control and logging extension. The vulnerabilities allow arbitrary code execution during CVS file commits if a filename is specially crafted to contain shell commands.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/48627/OpenPKG-SA-2006.014.txt
Source: https://packetstormsecurity.com/files/48627/OpenPKG-Security-Advisory-2006.14.html

