CVE-2017-8805: Debian Ftpsync
Critical severity, CVSS 9.1. EPSS: 3% chance of exploitation in the next 30 days.
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
Affected products
- Debian Ftpsync: up to and including 20171016
Published 2017-10-17. Last modified 2026-06-17.