Debian Security Advisory DSA 742-1 - Derek Price, the current maintainer of CVS, discovered a buffer overflow in the CVS server, that serves the popular Concurrent Versions System, which could lead to the execution of arbitrary code.
Gentoo Linux Security Advisory GLSA 200504-16 - Alen Zukich has discovered several serious security issues in CVS, including at least one buffer overflow (CVE-2005-0753), memory leaks and a NULL pointer dereferencing error. Versions less than 1.11.18-r1 are affected.
SUSE Security Announcement - Buffer overflow and memory access problems in cvs have been resolved.