CVE-2017-8805: Path Traversal
Published Oct 17, 2017
·Updated
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
Affected Software
1 affected component
Debian ftpsync<=20171016
Remediation
Patch Available
Event History
Oct 17, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8805?
CVE-2017-8805 has a medium severity rating due to its potential for directory traversal attacks.
2
How do I fix CVE-2017-8805?
To fix CVE-2017-8805, upgrade Debian ftpsync to version 20171017 or later which implements the --safe-links option.
3
What types of attacks can CVE-2017-8805 facilitate?
CVE-2017-8805 can facilitate directory traversal attacks, allowing attackers to access restricted files.
4
Which versions of Debian ftpsync are affected by CVE-2017-8805?
CVE-2017-8805 affects Debian ftpsync versions before 20171017, specifically those up to and including 20171016.
5
Is CVE-2017-8805 a local or remote vulnerability?
CVE-2017-8805 is a remote vulnerability, allowing attackers to exploit it from a distance.