Re: CVE-2026-11460 - security flaw in serialization
Rainer Deyke via Boost <[email protected]> Tue, 23 Jun 2026 08:17:56 +0200
| Newsgroups | gmane.comp.lib.boost.devel |
|---|---|
| Message-ID | <[email protected]> |
On 6/23/26 07:44, Robert Ramey via Boost wrote: > These components - checksum archive, composition archive would be > described/documented as. examples in updated/extended documentation of > the serialization library build with Boost Book. > > Soooooo ... That's my answer The problem isn't tampering. Tampering implies a hostile man-in-the-middle between trusted endpoints. The problem is that the endpoints cannot, and shouldn't have to, trust each other in the first place. -- Rainer Deyke - [email protected] _______________________________________________ Boost mailing list -- [email protected] To unsubscribe send an email to [email protected] https://lists.boost.org/mailman3/lists/boost.lists.boost.org/ Archived at: https://lists.boost.org/archives/list/[email protected]/message/PFWV5UMRHHEGGJXYVTSVCSZZM7LCO7CQ/