Let users install any APT package from hardcoded repositories
If I remember correctly the person:
-----BEGIN PGP MESSAGE-----
hF4DTQa9Wom5MBgSAQdA1bMaE+yZxaRIHbloetaDUB9czu7aYcN8QDXzr+oDyCYw
a7aguVGYEkgcEXm+SX9N7EPWTjhdSRfb/mIKkkQ3dDoPkmJhuZcgUh7LlVKWKTJV
0kcBVXI/2Qslf2aezB+ZMg3gDYd36vZLckhpXA7K3YaOdNVC2+09ImDenCh0Az5b
bqDdXIaELt81UUJFUEk0A69QqGReebjYtA==
=csgh
-----END PGP MESSAGE-----
mentioned me that if not well restrained, such APT sudo
can result in arbitrary root
command execution.
Would help the issue comment:
-----BEGIN PGP MESSAGE-----
hF4DTQa9Wom5MBgSAQdAEaLyuHpQcQosb2mplIK1+RLqcbIgX46it1FgW1R+2xow
JiVl7WanFovvwZ1otoabuNPb2fkSMdf5lSr2rnFN7SmT95X2MAuaaxDRx4cV9gVj
0q4BNKFST8HIrKpChUPI2e7NKCU5KaXYTadykGtHfSlHaLU5mzRfFltsnLa1UM6x
iTnyZg+Z0WxX5I9xf5tA52GBwGyquMVO8JN8Wq6jZSK2Qp5irCLf4N4lW1rf6n/6
k+rqcIIRGSfv45Df4ROwv7hXDtZIcLhPCt27PDlCW4ts7zbQ/S57SEBRhnSGCphD
lF/FUIOul6pcUQvG85iKrjucn1faWW0HjEsNjtO/bwo=
=ch3z
-----END PGP MESSAGE-----