SUSE-SU-2017:0431-1
Dashboard / Vulnerabilities / SUSE-SU-2017:0431-1
SUSE-SU-2017:0431-1
Summary: Security update for nodejs6
Details: This update for nodejs6 fixes the following issues: New upstream LTS release 6.9.5. The embedded openssl sources were updated to 1.0.2k (CVE-2017-3731, CVE-2017-3732, CVE-2016-7055, bsc#1022085, bsc#1022086, bsc#1009528) Other fixes: - Add basic check that Node.js loads successfully to spec file - New upstream LTS release 6.9.3 * build: shared library support is now working for AIX builds * deps/npm: upgrade npm to 3.10.10 * deps/V8: destructuring of arrow function arguments via computed property no longer throws * inspector: /json/version returns object, not an object wrapped in an array * module: using --debug-brk and --eval together now works as expected * process: improve performance of nextTick up to 20% * repl: the division operator will no longer be accidentally parsed as regex * repl: improved support for generator functions * timers: recanceling a cancelled timers will no longer throw - New upstream LTS version 6.9.2
References: https://www.suse.com/support/update/announcement/2017/suse-su-20170431-1/, https://bugzilla.suse.com/1009528, https://bugzilla.suse.com/1022085, https://bugzilla.suse.com/1022086, https://www.suse.com/security/cve/CVE-2016-7055, https://www.suse.com/security/cve/CVE-2017-3731, https://www.suse.com/security/cve/CVE-2017-3732
Affected packages
Package
Name: nodejs6
Purl: pkg:rpm/suse/nodejs6&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
Affected ranges
Type: ECOSYSTEM
Events:
