Bug 9114 - boost new security issue CVE-2013-0252
Summary: boost new security issue CVE-2013-0252
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: i586 Linux
Priority: Normal major
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact:
URL: http://lwn.net/Vulnerabilities/538848/
Whiteboard: MGA2TOO
Keywords:
Depends on: 9127
Blocks:
  Show dependency treegraph
 
Reported: 2013-02-19 02:37 CET by David Walser
Modified: 2013-03-24 16:46 CET (History)
2 users (show)

See Also:
Source RPM: boost-1.52.0-3.mga3.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2013-02-19 02:37:03 CET
Ubuntu has issued an advisory today (February 18):
http://www.ubuntu.com/usn/usn-1727-1/

Mageia 2 is also affected.

There is also an upstream advisory:
http://www.boost.org/users/news/boost_locale_security_notice.html
David Walser 2013-02-19 02:37:19 CET

CC: (none) => shlomif

David Walser 2013-02-19 02:37:29 CET

Assignee: bugsquad => shlomif

David Walser 2013-02-19 04:06:20 CET

Whiteboard: (none) => MGA2TOO

David Walser 2013-02-20 12:34:42 CET

CC: (none) => zen25000

David Walser 2013-02-20 12:39:46 CET

Depends on: (none) => 9127

Comment 1 David Walser 2013-03-15 16:17:12 CET
Can we get this pushed in Cauldron?

I know a couple packages don't build with it, but it's no worse than the current one in that regard.  We need to get this fixed.
Comment 2 David Walser 2013-03-24 16:46:04 CET
Fixed by Funda in boost-1.52.0-4.mga3.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.