Insecure Deserialization and Memory-Based Confusion Attacks in Boost Serialization
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 15/100
Research direction
Start with issue #331 and the available description of the Boost Serialization vulnerability. The technical details are temporarily redacted and discussion with maintainers is ongoing, so no file, test, entry point, or completion condition is identified yet.
Written by the indexing model from the issue text.
Description
An issue was discovered in Boost Serialization v1.89.0 and below. Insecure deserialization of untrusted input under certain conditions may lead to type confusion and ownership confusion, -- redacted --.
-- details redacted temporarily, discussion with maintainers ongoing --
- Dominant language
- C++
- Stars
- 135
- Forks
- 148
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from boostorg/serialization
-
infinity Open
Difficulty 3/5 1-2 days Newbie friendliness 55/100
boostorg/serialization#386 · 1 comment ·
-
waiting-for-input
Difficulty 4/5 3-5 days Newbie friendliness 35/100
boostorg/serialization#183 · 22 comments ·
All issues in boostorg/serialization
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
AXERA-TECH/ax-llm#77 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
games-on-whales/wolf#509 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
bug-unconfirmed
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
NVIDIA/cuda-samples#453 ·