Security update for cvs

This update for cvs fixes the following issues:

- CVE-2017-12836: A leading dash in the argument of the "-d" option could lead to argument injection (bsc#1053364)

This update was imported from the SUSE:SLE-12:Update update project.

Fixed bugs
bnc#1053364
VUL-0: CVE-2017-12836: cvs: client code execution via argument injection in SSH URL
Selected Binaries
openSUSE Build Service is sponsored by