{"id":"UBUNTU-CVE-2017-8805","details":"Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.","modified":"2025-07-16T07:37:19.993282Z","published":"2017-10-17T18:29:00Z","withdrawn":"2025-07-18T16:43:59Z","upstream":["CVE-2017-8805"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-8805"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2017/10/17/2"},{"type":"REPORT","url":"https://anonscm.debian.org/cgit/mirror/archvsync.git/commit/?id=d1ca2ab2210990b6dfb664cd6776a41b71c48016"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2017-8805"}],"affected":[{"package":{"name":"archvsync","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/archvsync@20171018?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20171018"}]}],"versions":["20170912"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ftpsync","binary_version":"20171018"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-8805.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}