Описание
Recommended update for boost-legacy
This update for boost-legacy fixes the following issues:
Create a new boost-legacy package with version 1.66.0. (bsc#1175886, jsc#SLE-17304, jsc#ECO-3147)
- Remove duplicate license package that we get from original Boost
- Add a backport of
Boost.Optional::has_value()for LibreOffice - Use
%licenseinstead of%doc(bsc#1082318) - Multibuild requires versioned
Name: tag. (bsc#1076640)
Changes in version 1.66.0:
Beast: new portable HTTP, WebSocket and network operations usingBoost.Asio. Header-only library.Callable Traits: new library and successor toBoost.FunctionTypes. Header-only library.Mp11:new metaprogramming libraryAsio:- implemented interface changes to reflect the Networking TS (N4656)
- functions and classes that have been superseded by Networking TS functionality have been deprecated.
- added support for customized handler tracking
- removed previously deprecated functions
Atomic: improved compatibility with GCC 7. 128-bit operations onx86_64no longer require linking with compiled library.DateTime: Fixed an integral overflow that could cause incorrect results when adding or subtracting many years from a date.Format: New format specifiers added and volatile arguments can not be safely used with operator%Fusion:- fix compile error with
std::array - remove circular preprocessor include
- fix compile error with
PolyCollection: backported to GCC 4.8 and 4.9 with some limitationsUuid: addedRTF-4122namespaces inboost::uuids::ns
Список пакетов
SUSE Linux Enterprise Module for Legacy 15 SP2
libboost_locale_legacy-1.66.0-1.4.1
libboost_regex_legacy-1.66.0-1.4.1
Ссылки
- Link for SUSE-RU-2021:1414-1
- E-Mail link for SUSE-RU-2021:1414-1
- SUSE Security Ratings
- SUSE Bug 1006584
- SUSE Bug 1038083
- SUSE Bug 1076640
- SUSE Bug 1082318
- SUSE Bug 1175886
- SUSE Bug 401964
- SUSE Bug 439805
- SUSE Bug 457699
- SUSE Bug 461372
- SUSE Bug 477603
- SUSE Bug 479659
- SUSE Bug 544958
- SUSE Bug 621140
- SUSE Bug 655747
- SUSE Bug 714373
- SUSE Bug 765443
- SUSE Bug 951902
Описание
regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.
Затронутые продукты
SUSE Linux Enterprise Module for Legacy 15 SP2:libboost_locale_legacy-1.66.0-1.4.1
SUSE Linux Enterprise Module for Legacy 15 SP2:libboost_regex_legacy-1.66.0-1.4.1
Ссылки
- CVE-2008-0171
- SUSE Bug 353180