Reply to post: Re: Misses the point of serialisation...

Whisper this, but Java deserialisation vulnerability affects more libraries

Vincent Ballard

Re: Misses the point of serialisation...

Specifically, it's about deserialising classes from org.apache which use a deserialisation hook to parse their embedded data and execute a process defined by such data. This exploit would not be possible if attackers could only craft packets containing classes which I've written and which don't do such crazy things. (Of course, that doesn't mean that there couldn't be any vulnerabilities, but they would be more specific).

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon