Critical severity9.1NVD Advisory· Published Oct 17, 2017· Updated May 13, 2026
CVE-2017-8805
CVE-2017-8805
Description
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
Affected products
2- Range: Debian ftpsync before 20171017
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.openwall.com/lists/oss-security/2017/10/17/2nvdIssue TrackingMailing ListPatchThird Party Advisory
- anonscm.debian.org/cgit/mirror/archvsync.git/commit/nvdIssue TrackingPatchVendor Advisory
- lists.debian.org/debian-mirrors/2017/10/msg00017.htmlnvdIssue TrackingMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.