boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes.
| Software | From | Fixed in |
|---|---|---|
| boost / boost | 1.52.0 | 1.52.0.x |
| boost / boost | 1.51.0 | 1.51.0.x |
| boost / boost | 1.50.0 | 1.50.0.x |
| boost / boost | 1.48.0 | 1.48.0.x |
| boost / boost | 1.49.0 | 1.49.0.x |