Debian Linux Security Advisory 3048-1 - Guillem Jover discovered that the changelog retrieval functionality in apt-get used temporary files in an insecure way, allowing a local user to cause arbitrary files to be overwritten.
e560fbde31ef78372c5c58e5fb97d1b738f7c6c631ba5bb62b24ae1c4645919c
Ubuntu Security Notice 2370-1 - Guillem Jover discovered that APT incorrectly created a temporary file when handling the changelog command. A local attacker could use this issue to overwrite arbitrary files. In the default installation of Ubuntu, this should be prevented by the kernel link restrictions.
f68baf3af6020849786748719a5425dd99fe459dd9f7340d1ac69932e7170a3e