Comment 2 for bug 1787752

Revision history for this message
Julian Andres Klode (juliank) wrote : Re: security issue in mirror:// - CVE-2018-0501

Summary and upgrade advise:

APT 1.6 and newer failed to verify InRelease files that were retrieved
as a fallback from one mirror to another when using the mirror:// method.

As the mirror method can thus not be trusted, it is suggested to replace
use of the mirror method in sources.list files with the standard http
method before upgrading to a fixed version.