boostorg / boostorg/serialization
Insecure Deserialization and Memory-Based Confusion Attacks in Boost Serialization
Open
waiting-for-input
- Dominant language
- C++
- Stars
- 134
- Forks
- 148
- Avg merge
- 2d 23h
- Merged PRs (30d)
- 5
Description
An issue was discovered in Boost Serialization v1.89.0 and below. Insecure deserialization of untrusted input under certain conditions may lead to type confusion and ownership confusion, *-- redacted --*.
*-- details redacted temporarily, discussion with maintainers ongoing --*
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.