CVS Feature Version 1.12.5 Released! <strong>(security update)</strong>

From: Derek Robert Price
Subject: CVS Feature Version 1.12.5 Released! <strong>(security update)</strong>
Date: Thu, 18 Dec 2003 16:57:32 -0500
Feature CVS 1.12.5 has been released.  Feature releases contain new
features as well as all the bug fixes from the stable releases.  This
release adds code to the CVS server to prevent it from continuing as
root after a user login, as an extra failsafe against a compromise of
the CVSROOT/passwd file.  Previously, any user with the ability to write
the CVSROOT/passwd file could execute arbitrary code as the root user on
systems with CVS pserver access enabled.  It also fixes some issues
compiling under windows and other issues compilng the large file support
on various platforms.  We recommend this upgrade for all CVS clients and
servers already running the feature release and for those who simply
like to stay on the cutting edge!

Take a look at the NEWS file
from the source distribution or go directly to the downloads page

MD5 sum:

eeacc440ad77e0671bffa0fd2900f419  cvs-1.12.5.tar.bz2

Public key availble from <http:/./pgp.mit.edu>
Public key fingerprint: CB6A 07CA 90C5 4234 E8A3 C8D0 2C3D 4E4C 17F2 31A4.

