Insecure Deserialization and Memory-Based Confusion Attacks in Boost Serialization
还没有人认领这个 Issue。
评估
调研方向
从 issue #331 以及现有的 Boost Serialization 漏洞描述开始。技术细节目前暂时被隐去,与维护者的讨论仍在进行,因此尚未确定任何文件、测试、入口点或完成条件。
由索引模型根据 Issue 内容生成。
描述
An issue was discovered in Boost Serialization v1.89.0 and below. Insecure deserialization of untrusted input under certain conditions may lead to type confusion and ownership confusion, -- redacted --.
-- details redacted temporarily, discussion with maintainers ongoing --
- 主要语言
- C++
- 星标
- 135
- 派生
- 148
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
boostorg/serialization 的其他 Issue
-
infinity 未关闭
难度 3/5 1-2 天 新手友好度 55/100
boostorg/serialization#386 · 1 条评论 ·
-
waiting-for-input
难度 4/5 3-5 天 新手友好度 35/100
boostorg/serialization#183 · 22 条评论 ·
查看 boostorg/serialization 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 90/100
AXERA-TECH/ax-llm#77 ·
-
难度 1/5 1 小时以内 新手友好度 90/100
games-on-whales/wolf#509 ·
-
难度 2/5 1-3 小时 新手友好度 74/100
-
bug-unconfirmed
难度 2/5 1-3 小时 新手友好度 76/100
-
难度 2/5 1-3 小时 新手友好度 74/100
NVIDIA/cuda-samples#453 ·