Bug#977994: apt: Output from sandboxed methods should not be trusted

2020-12-23 Thread Demi M. Obenour
Package: apt Version: 1.8.2.2 Severity: important Dear Maintainer, As far as I can tell, APT still trusts the output of its methods. This means that while they are sandboxed in theory, this sandbox is trivially escapable in practice. This would be Severity: critical except that no

Bug#977994: apt: Output from sandboxed methods should not be trusted

2020-12-31 Thread Demi M. Obenour
On 12/31/20 6:03 AM, David Kalnischkies wrote: > On Wed, Dec 30, 2020 at 09:32:32PM -0500, Demi M. Obenour wrote: >> That is true. Nevertheless, if we are going to put in the work to >> confine the methods, we should also make sure they cannot escape >> their confinement. >