| Summary: | nodejs security update fixes several flaws | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Stig-Ørjan Smelror <smelror> |
| Component: | RPM Packages | Assignee: | Joseph Wang <joequant> |
| Status: | RESOLVED DUPLICATE | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | ||
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://nodejs.org/en/blog/release/v8.8.0/ | ||
| Whiteboard: | |||
| Source RPM: | CVE: | ||
| Status comment: | CVE-2017-14919 | ||
|
Stig-Ørjan Smelror
2017-11-29 15:04:19 CET
Status comment:
(none) =>
CVE-2017-14919
Stig-Ørjan Smelror
2017-11-29 15:05:30 CET
Assignee:
bugsquad =>
joequant |
* crypto: -expose ECDH class #8188 * http2: -http2 is now exposed by default without the need for a flag #15685 -a new environment variable NODE_NO_HTTP2 has been added to allow userland http2 to be required #15685 -support has been added for generic Duplex streams #16269 * module: -resolve and instantiate loader pipeline hooks have been added to the ESM lifecycle #15445 * zlib: -CVE-2017-14919 - In zlib v1.2.9, a change was made that causes an error to be raised when a raw deflate stream is initialized with windowBits set to 8. On some versions this crashes Node and you cannot recover from it, while on some versions it throws an exception. Node.js will now gracefully set windowBits to 9 replicating the legacy behavior to avoid a DOS vector. nodejs-private/node-private#95