The mirror package is a tool that duplicates the content of ftp servers. A vulnerability in that package allows attackers to create directories like ".." on the target mirror ftp server, enabling the creation of files one level above the local target directory for the mirrored files.
Credit:
The information has been provided by: Marc Heuse.