Sicherheit: Denial of Service in node.js
Aktuelle Meldungen Distributionen
Name: Denial of Service in node.js
ID: FEDORA-2017-c582c1e728
Distribution: Fedora
Plattformen: Fedora 25
Datum: Mi, 8. November 2017, 06:54
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14919
Applikationen: node.js


Fedora Update Notification
2017-11-07 22:23:37.427135

Name : nodejs
Product : Fedora 25
Version : 6.11.5
Release : 1.fc25
URL : http://nodejs.org/
Summary : JavaScript runtime
Description :
Node.js is a platform built on Chrome's JavaScript runtime
for easily building fast, scalable network applications.
Node.js uses an event-driven, non-blocking I/O model that
makes it lightweight and efficient, perfect for data-intensive
real-time applications that run across distributed devices.

Update Information:

# 2017-10-24, Version 6.11.5 'Boron' (LTS), @MylesBorins This is a
release. All Node.js users should consult the security release summary at
https://nodejs.org/en/blog/vulnerability/oct-2017-dos/ for details on patched
vulnerabilities. ## Notable Changes * zlib: * CVE-2017-14919 - In zlib
v1.2.9, a change was made that causes an error to be raised when a raw deflate
stream is initialized with windowBits set to 8. On some versions this crashes
Node and you cannot recover from it, while on some versions it throws an
exception. Node.js will now gracefully set windowBits to 9 replicating the
legacy behavior to avoid a DOS vector. nodejs-private/node-private#95

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade nodejs' at the command line.
For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Pro-Linux @Facebook
Neue Nachrichten