Re: CVE-2026-11460 - security flaw in serialization

Rainer Deyke via Boost <[email protected]> Tue, 23 Jun 2026 08:17:56 +0200
Newsgroups gmane.comp.lib.boost.devel
Message-ID <[email protected]>
On 6/23/26 07:44, Robert Ramey via Boost wrote:
> These components - checksum archive, composition archive would be 
> described/documented as. examples in updated/extended documentation of 
> the serialization library build with Boost Book.
> 
> Soooooo ... That's my answer

The problem isn't tampering.  Tampering implies a hostile 
man-in-the-middle between trusted endpoints.  The problem is that the 
endpoints cannot, and shouldn't have to, trust each other in the first 
place.


-- 
Rainer Deyke - [email protected]

_______________________________________________
Boost mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://lists.boost.org/mailman3/lists/boost.lists.boost.org/
Archived at: https://lists.boost.org/archives/list/[email protected]/message/PFWV5UMRHHEGGJXYVTSVCSZZM7LCO7CQ/