CVE-2013-0252: Boost

Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.

boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes.

Affected products

  • Boost Boost: version 1.48.0 only; version 1.49.0 only; version 1.50.0 only; version 1.51.0 only; version 1.52.0 only

Published 2013-03-12. Last modified 2026-06-16.