Subject: CVS commit: pkgsrc/devel/cvs
To: None <pkgsrc-changes@NetBSD.org>
From: Thomas Klausner <wiz@netbsd.org>
List: pkgsrc-changes
Date: 05/22/2004 10:38:06
Module Name:	pkgsrc
Committed By:	wiz
Date:		Sat May 22 10:38:06 UTC 2004

Modified Files:
	pkgsrc/devel/cvs: Makefile distinfo
	pkgsrc/devel/cvs/patches: patch-aa patch-ab patch-af patch-al patch-am
	    patch-ar patch-at patch-au

Log Message:
Update to 1.11.16:
Changes since 1.11.15:
**********************

SERVER SECURITY FIXES

* A potential buffer overflow vulnerability in the server has been fixed.
  Prior to this patch, a malicious client could potentially use carefully
  crafted server requests to run arbitrary programs on the CVS server machine.
  This addresses the Common Vulnerabilities and Exposures Project's issue
  #CAN-2004-0396.  Please see <http://www.cve.mitre.org> for more information.

BUG FIXES

* The Microsoft Visual C++ workspace and project files have been repaired and
  regenerated with MSVC++ 6.0.

* The cvs.1 man page is now generated automatically from a section of the CVS
  Manual.

* Thanks to a report from Mark Andrews at the Internet Systems Consortium, the
  :ext: connection method no longer relies on a transparent transport that uses
  an argument processor that can handle arbitrary ordering of options and other
  arguments when using a username other than the caller's.

* Thanks to Ken Raeburn at MIT, directory deletion, whether via `cvs release'
  or empty directory pruning, now works on network shares under Windows XP.


To generate a diff of this commit:
cvs rdiff -r1.76 -r1.77 pkgsrc/devel/cvs/Makefile
cvs rdiff -r1.19 -r1.20 pkgsrc/devel/cvs/distinfo
cvs rdiff -r1.9 -r1.10 pkgsrc/devel/cvs/patches/patch-aa \
    pkgsrc/devel/cvs/patches/patch-af
cvs rdiff -r1.11 -r1.12 pkgsrc/devel/cvs/patches/patch-ab
cvs rdiff -r1.8 -r1.9 pkgsrc/devel/cvs/patches/patch-al
cvs rdiff -r1.10 -r1.11 pkgsrc/devel/cvs/patches/patch-am \
    pkgsrc/devel/cvs/patches/patch-at
cvs rdiff -r1.12 -r1.13 pkgsrc/devel/cvs/patches/patch-ar
cvs rdiff -r1.7 -r1.8 pkgsrc/devel/cvs/patches/patch-au

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.