Boost logo

Boost :

Subject: [boost] [Locale] Security bug announcement - UTF-8 validation
From: Artyom Beilis (artyomtnk_at_[hidden])
Date: 2013-01-04 09:15:27

Hello, Boost.Locale library in Boost 1.48 to 1.52 including has a security flow. boost::locale::utf::utf_traits accepted some invalid UTF-8 sequences. Applications that used these functions for UTF-8 input validation could expose themself to security threats as invalid UTF-8 sequece would be considered as valid. This bug is fixed in upcoming Boost 1.53. For more details see: Users who can't upgrade to the latest versions may apply the following patch to fix the problem. Regards,   Artyom Beilis -------------- CppCMS - C++ Web Framework: CppDB - C++ SQL Connectivity:

Boost list run by bdawes at, gregod at, cpdaniel at, john at