Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2021:1414-1

Опубликовано: 28 апр. 2021
Источник: suse-cvrf

Описание

Recommended update for boost-legacy

This update for boost-legacy fixes the following issues:

Create a new boost-legacy package with version 1.66.0. (bsc#1175886, jsc#SLE-17304, jsc#ECO-3147)

  • Remove duplicate license package that we get from original Boost
  • Add a backport of Boost.Optional::has_value() for LibreOffice
  • Use %license instead of %doc (bsc#1082318)
  • Multibuild requires versioned Name: tag . (bsc#1076640)

Changes in version 1.66.0:

  • Beast: new portable HTTP, WebSocket and network operations using Boost.Asio. Header-only library.
  • Callable Traits: new library and successor to Boost.FunctionTypes. Header-only library.
  • Mp11: new metaprogramming library
  • Asio:
    • implemented interface changes to reflect the Networking TS (N4656)
    • functions and classes that have been superseded by Networking TS functionality have been deprecated.
    • added support for customized handler tracking
    • removed previously deprecated functions
  • Atomic: improved compatibility with GCC 7. 128-bit operations on x86_64 no longer require linking with compiled library.
  • DateTime: Fixed an integral overflow that could cause incorrect results when adding or subtracting many years from a date.
  • Format: New format specifiers added and volatile arguments can not be safely used with operator%
  • Fusion:
    • fix compile error with std::array
    • remove circular preprocessor include
  • PolyCollection: backported to GCC 4.8 and 4.9 with some limitations
  • Uuid: added RTF-4122 namespaces in boost::uuids::ns

Список пакетов

SUSE Linux Enterprise Module for Legacy 15 SP2
libboost_locale_legacy-1.66.0-1.4.1
libboost_regex_legacy-1.66.0-1.4.1

Описание

regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.


Затронутые продукты
SUSE Linux Enterprise Module for Legacy 15 SP2:libboost_locale_legacy-1.66.0-1.4.1
SUSE Linux Enterprise Module for Legacy 15 SP2:libboost_regex_legacy-1.66.0-1.4.1

Ссылки
Уязвимость SUSE-RU-2021:1414-1