filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16929
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1452
http://www.securityfocus.com/bid/10878
http://www.kb.cert.org/vuls/id/770816
http://www.cvstrac.org/cvstrac/tktview?tn=339
http://www.cvstrac.org/cvstrac/chngview?cn=316