> as Ubuntu package will have same files structured exactly same way as Debian one.
As opposed to what? If Ubuntu uses the same source, of course they get the same binaries. And if Ubuntu applies patches, they'll get something different. And that's still true.
If anything it will make attacker's job easier, as Ubuntu package will have same files structured exactly same way as Debian one.