boostorg / boostorg/serialization

Insecure Deserialization and Memory-Based Confusion Attacks in Boost Serialization

Open
#331 1 comment 0 reactions 0 assignees View on GitHub
waiting-for-input
Dominant language
C++
Stars
134
Forks
148
Avg merge
2d 23h
Merged PRs (30d)
5

Description

An issue was discovered in Boost Serialization v1.89.0 and below. Insecure deserialization of untrusted input under certain conditions may lead to type confusion and ownership confusion, *-- redacted --*.

*-- details redacted temporarily, discussion with maintainers ongoing --*

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.