The remote host is missing updates announced in advisory GLSA 200406-06.
All CVS users should upgrade to the latest stable version: # emerge sync # emerge -pv '>=dev-util/cvs-1.11.17' # emerge '>=dev-util/cvs-1.11.17' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200406-06 http://bugs.gentoo.org/show_bug.cgi?id=53408 http://security.e-matters.de/advisories/092004.html
Several serious new vulnerabilities have been found in CVS, which may allow an attacker to remotely compromise a CVS server.
CVE CVE-2004-0414, CVE-2004-0416, CVE-2004-0417, CVE-2004-0418
CVSS Base Score: 10.0