Sandbox external processes

Mat2 is using a lot of software with a long history of vulnerabilities (poppler, cairo, ffmpeg, …). We should sandbox them.