TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Debian Security Advisory: DSA-3025-1 apt

175 pointsby handsomeransomsover 10 years ago

6 comments

brockersover 10 years ago
Honestly, I wonder how many people here are going to worry about apt file signature verification while simultaneously running "bundle install" with a gemfile containing 50 sources including random github HEADs.
评论 #8331661 未加载
评论 #8332308 未加载
评论 #8331194 未加载
评论 #8331280 未加载
评论 #8331137 未加载
ayrxover 10 years ago
So... Debian users will need to grab security fixes for `apt-get` using... `apt-get`?
评论 #8330653 未加载
评论 #8330976 未加载
评论 #8330613 未加载
评论 #8330487 未加载
评论 #8330563 未加载
评论 #8330472 未加载
评论 #8331362 未加载
JacobEdelmanover 10 years ago
Anyone know how long these bugs have been around or if they have been exploited?
评论 #8331162 未加载
0x0over 10 years ago
Is there an easy way to re-validate that previously installed .debs haven&#x27;t been modified? Perhaps a script to at least check all the debs in the local apt archive cache?<p>Also, does it really affect regular apt-get upgrades? &quot;apt-get download&quot; isn&#x27;t a common way to run apt.
评论 #8330915 未加载
评论 #8330795 未加载
sauereover 10 years ago
That feel when you see a Debian Security Advisory on the top of HN. Common guys, don&#x27;t scare me to death. It thought this was going to be heartbleed all over again.
评论 #8332627 未加载
morganvachonover 10 years ago
Seeing this almost makes me want to switch back to Slackware for good. Using a Debian based OS has made me lazy; I love the convenience of being able to apt-get whatever I want to install instead of downloading the source and building my own packages. But when you can&#x27;t even trust the package manager on the most widespread* distro? Basically every single package on my system is now suspect (I did immediately upgrade apt but any damage is already done).<p>*Speaking in terms of the number of derivatives that also use apt
评论 #8330659 未加载
评论 #8330711 未加载