Find real vulnerabilities before they ship
Vulnerability Database › CVE-2000-0679
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.