Upstream has issued an advisory on December 4: https://nodejs.org/en/blog/vulnerability/december-2015-security-releases/ The issue is fixed upstream in 0.10.41: https://nodejs.org/en/blog/release/v0.10.41/ Mageia 5 is also affected. Reproducible: Steps to Reproduce:
Whiteboard: (none) => MGA5TOO
Joseph updated Cauldron to version 5.3.0. I just noticed that CVE-2015-8027 doesn't affect 0.10.x. I'll open a new bug for the 0.10.41 bugfix release.
Status: NEW => RESOLVEDResolution: (none) => FIXEDWhiteboard: MGA5TOO => (none)