Two vulnerabilities have been discovered and fixed in CVS:
Sebastian Krahmer discovered a vulnerability whereby a malicious CVS pserver could create arbitrary files on the client system during an update or checkout operation, by supplying absolute pathnames in RCS diffs.
Derek Robert Price discovered a vulnerability whereby a CVS pserver could be abused by a malicious client to view the contents of certain files outside of the CVS root directory using relative pathnames containing "../".
For the current stable distribution (woody) these problems have been fixed in version 1.11.1p1debian-9woody2.
For the unstable distribution (sid), these problems will be fixed soon.
We recommend that you update your cvs package.
MD5 checksums of the listed files are available in the original advisory.