It was discovered that APT, the high level package manager, does not
properly invalidate unauthenticated data (CVE-2014-0488),
performs incorrect verification of 304 replies (CVE-2014-0487)
and does not perform the checksum check when the Acquire::GzipIndexes option is used
(CVE-2014-0489).
For Debian 6 Squeeze, these issues have been fixed in apt version 0.8.10.3+squeeze3