APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.
Exploitability
AV:NAC:LAu:NImpact
C:PI:PA:P7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P