The Debian Project announced yesterday the general availability of the seventh update to the Debian GNU/Linux 9 “Stretch” operating system series, to address the recently discovered security vulnerability in APT.
A security vulnerability affects the APT Package Manager in Debian GNU/Linux and Ubuntu, as well as other derivatives of both, allowing a remote attacker to install malicious packages on users' machines. APT treated the packages as valid, thus allowing the attacker to execute code as root and potentially destroy the host computer.
Both Debian and Ubuntu released patched versions of APT in their supported distributions, but the Debian Project also released the Debian GNU/Linux 9.7 “Stretch” version, to avoid any complications in new implementations of their operating system.
“The Debian Project is pleased to announce the 7th update of the stable Debian 9 distribution (codename stretch), which incorporates the recent security update for APT, to ensure that new stretch installations are not vulnerable,” the update announcement states
Debian GNU/Linux 9.7 “Stretch” ISO images coming soon
As with any release of the Debian GNU/Linux operating system, you do not need to download new ISO images to update your existing installations, especially this time, as the Debian GNU/Linux 9.7 “Stretch” release only contains a new version of the APT package manager, which is no longer vulnerable to “man-in-the-middle” attacks
However, the Debian Project will release live install-only ISO images for all supported architectures of Debian GNU/Linux 9.7 “Stretch,” which will be available for download in the coming days. In the meantime, make sure to update your installations.
