It was discovered that reprepro, a tool to create a repository of Debian packages, only checks the validity of known signatures when updating from a remote site, and thus does not reject packages with only unknown signatures. This allows an attacker to bypass this authentication mechanism.
The oldstable distribution (sarge) is not affected by this problem.
For the stable distribution (etch) this problem has been fixed in version 1.3.1+1-1.
For the unstable distribution (sid) this problem has been fixed in version 2.2.4-1.
We recommend that you upgrade your reprepro package.
MD5 checksums of the listed files are available in the original advisory.