Page 1 of 1

Java Apocalypse - Deserialization Flaw

Posted: 18 Nov 2018 23:59
by anonymousmaybe
Its better to check if I2P or any of its applications used by default effected by this flaw:

- Deserialization issues also affect Ruby, not just Java, PHP, and .NET
https://www.zdnet.com/article/deseriali ... p-and-net/

If I2P and all its applications happened to be safe from this attack , please announce that on I2P website. (common attacks or anywhere ...)

Re: Java Apocalypse - Deserialization Flaw

Posted: 19 Nov 2018 10:00
by echelon
Hi

the issue is 3 years old now, and as I2P itself does not use these functions, I2P itself is secure against this attacks, AFAIK.

We cannot talk for other apps, though.

echelon