Joe Smith wrote:
It would still be possible to mount this attack if the attacker can intercept packets on the way to the official trusted security mirror and redirect them (e.g. transparent proxy) to an older copy of the mirror.However, if the security updates come from trusted security mirrors rather than a general mirror, that attack would fail too. So with the exception of Sid or Testing users that do not use the testing-security system to receive securityupdates, Debian really is not terribly vulnerable to this.
Brian May