[Buildroot] [PATCH] nodejs: security bump to version 8.14.0

Peter Korsgaard peter at korsgaard.com
Sun Dec 16 21:10:18 UTC 2018


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security vulnerabilities:
 > - Node.js: Denial of Service with large HTTP headers (CVE-2018-12121)
 > - Node.js: Slowloris HTTP Denial of Service (CVE-2018-12122 / Node.js)
 > - Node.js: Hostname spoofing in URL parser for javascript protocol
 >   (CVE-2018-12123)
 > - Node.js: HTTP request splitting (CVE-2018-12116)
 > - OpenSSL: Timing vulnerability in DSA signature generation (CVE-2018-0734)
 > - OpenSSL: Microarchitecture timing vulnerability in ECC scalar
 >   multiplication (CVE-2018-5407)

 > For more details, see the announcement:
 > https://nodejs.org/en/blog/release/v8.14.0/

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2018.02.x, 2018.08.x and 2018.11.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list