This fix addresses this paper: http://www.cs.arizona.edu/people/justin/packagemanagersecurity/attacks- on-package-managers.html
-- smart does not correctly verify packages coming from archives. https://bugs.launchpad.net/bugs/267901 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs