Debian Security Advisory 1394-1 – It was discovered that reprepro, a tool to create a repository of Debian packages, when updating from a remote site only checks for the validity of known signatures, and thus does not reject packages with only unknown signatures. This allows an attacker to bypass this authentication mechanism.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60372/dsa-1394-1.txt
Source: https://packetstormsecurity.com/files/60372/Debian-Linux-Security-Advisory-1394-1.html

