Vulnerability Bulletins

DSA-3733 apt - security update

   
Affected software Debian
 
Jann Horn of Google Project Zero discovered that APT, the high levelpackage manager, does not properly handle errors when validatingsignatures on InRelease files. An attacker able to man-in-the-middleHTTP requests to an apt repository that uses InRelease files(clearsigned Release files), can take advantage of this flaw tocircumvent the signature of the InRelease file, leading to arbitrarycode execution.

More info:

https://www.debian.org/security/2016/dsa-3733