Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
CVSS Metrics