CVE-2013-0252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/03/2013
Last modified:
05/12/2013

Description

boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:boost:boost:1.48.0:*:*:*:*:*:*:*
cpe:2.3:a:boost:boost:1.49.0:*:*:*:*:*:*:*
cpe:2.3:a:boost:boost:1.50.0:*:*:*:*:*:*:*
cpe:2.3:a:boost:boost:1.51.0:*:*:*:*:*:*:*
cpe:2.3:a:boost:boost:1.52.0:*:*:*:*:*:*:*