Re: [R] De-serialization vulnerability?

2024-05-02 Thread peter dalgaard
As a general matter, security holes are usually not advertised by detailing them in the NEWS file. The disclosure of such things goes on a different schedule, typically _after_ binaries are out, at which point editing the NEWS file is too late. There are other things that do not go into

Re: [R] De-serialization vulnerability?

2024-05-01 Thread Ivan Krylov via R-help
В Wed, 1 May 2024 16:57:18 + "Howard, Tim G \(DEC\) via R-help" пишет: > Is this real? Yes, but with a giant elephant in the room that many are overlooking. It has actually always been much worse. Until R-4.4.0, there used to be a way for readRDS() to return an unevaluated "promise