Ubuntu Security Notice 1477-1 - Georgi Guninski discovered that APT did not properly validate imported keyrings via apt-key net-update. USN-1475-1 added additional verification for imported keyrings, but it was insufficient. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. This update corrects the issue by disabling the net-update option completely. A future update will re-enable the option with corrected verification.
1b4ff29ca5b7fc7085d8b6d331ed19fb7e6e91ec24cca1f134369b5b2de67564