--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2017-5c17b4934f
2017-11-15 19:03:16.423054
--------------------------------------------------------------------------------Name        : nodejs
Product     : Fedora 26
Version     : 6.11.5
Release     : 1.fc26
URL         : http://nodejs.org/
Summary     : JavaScript runtime
Description :
Node.js is a platform built on Chrome's JavaScript runtime
for easily building fast, scalable network applications.
Node.js uses an event-driven, non-blocking I/O model that
makes it lightweight and efficient, perfect for data-intensive
real-time applications that run across distributed devices.

--------------------------------------------------------------------------------Update Information:

# 2017-10-24, Version 6.11.5 'Boron' (LTS), @MylesBorins  This is a security
release. All Node.js users should consult the security release summary at
https://nodejs.org/en/blog/vulnerability/oct-2017-dos/ for details on patched
vulnerabilities.  ## Notable Changes  * zlib:     * CVE-2017-14919 - In zlib
v1.2.9, a change was made that causes an error to be raised when a raw deflate
stream is initialized with windowBits set to 8. On some versions this crashes
Node and you cannot recover from it, while on some versions it throws an
exception. Node.js will now gracefully set windowBits to 9 replicating the
legacy behavior to avoid a DOS vector. nodejs-private/node-private#95
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade nodejs' at the command line.
For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora 26: nodejs Security Update

November 15, 2017
# 2017-10-24, Version 6.11.5 'Boron' (LTS), @MylesBorins This is a security release

Summary

Node.js is a platform built on Chrome's JavaScript runtime

for easily building fast, scalable network applications.

Node.js uses an event-driven, non-blocking I/O model that

makes it lightweight and efficient, perfect for data-intensive

real-time applications that run across distributed devices.

# 2017-10-24, Version 6.11.5 'Boron' (LTS), @MylesBorins This is a security

release. All Node.js users should consult the security release summary at

https://nodejs.org/en/blog/vulnerability/oct-2017-dos/ for details on patched

vulnerabilities. ## Notable Changes * zlib: * CVE-2017-14919 - In zlib

v1.2.9, a change was made that causes an error to be raised when a raw deflate

stream is initialized with windowBits set to 8. On some versions this crashes

Node and you cannot recover from it, while on some versions it throws an

exception. Node.js will now gracefully set windowBits to 9 replicating the

legacy behavior to avoid a DOS vector. nodejs-private/node-private#95

su -c 'dnf upgrade nodejs' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

FEDORA-2017-5c17b4934f 2017-11-15 19:03:16.423054 Product : Fedora 26 Version : 6.11.5 Release : 1.fc26 URL : http://nodejs.org/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. # 2017-10-24, Version 6.11.5 'Boron' (LTS), @MylesBorins This is a security release. All Node.js users should consult the security release summary at https://nodejs.org/en/blog/vulnerability/oct-2017-dos/ for details on patched vulnerabilities. ## Notable Changes * zlib: * CVE-2017-14919 - In zlib v1.2.9, a change was made that causes an error to be raised when a raw deflate stream is initialized with windowBits set to 8. On some versions this crashes Node and you cannot recover from it, while on some versions it throws an exception. Node.js will now gracefully set windowBits to 9 replicating the legacy behavior to avoid a DOS vector. nodejs-private/node-private#95 su -c 'dnf upgrade nodejs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
Product : Fedora 26
Version : 6.11.5
Release : 1.fc26
URL : http://nodejs.org/
Summary : JavaScript runtime

Related News