Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD prior to 1.11.2 allows local users to execute arbitrary code.
distrotech cvs