CVE-2017-8805: Debian Ftpsync

Critical severity, CVSS 9.1. EPSS: 3% chance of exploitation in the next 30 days.

Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.

Affected products

  • Debian Ftpsync: up to and including 20171016

Published 2017-10-17. Last modified 2026-06-17.