CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
www.idefense.com/application/poi/display?id=130&type=vulnerabilities
www.kb.cert.org/vuls/id/579225
www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108
www.securityfocus.com/bid/10955
exchange.xforce.ibmcloud.com/vulnerabilities/17001
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10688