Security update for nodejs6
This update for nodejs6 fixes the following issues: New upstream LTS release 6.9.5. The embedded openssl sources were updated to 1.0.2k (CVE-2017-3731, CVE-2017-3732, CVE-2016-7055, bsc#1022085, bsc#1022086, bsc#1009528) Other fixes: - Add basic check that Node.js loads successfully to spec file - New upstream LTS release 6.9.3 * build: shared library support is now working for AIX builds * deps/npm: upgrade npm to 3.10.10 * deps/V8: destructuring of arrow function arguments via computed property no longer throws * inspector: /json/version returns object, not an object wrapped in an array * module: using --debug-brk and --eval together now works as expected * process: improve performance of nextTick up to 20% * repl: the division operator will no longer be accidentally parsed as regex * repl: improved support for generator functions * timers: recanceling a cancelled timers will no longer throw - New upstream LTS version 6.9.2
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for nodejs6 fixes the following issues: New upstream LTS release 6.9.5. The embedded openssl sources were updated to 1.0.2k (CVE-2017-3731, CVE-2017-3732, CVE-2016-7055, bsc#1022085, bsc#1022086, bsc#1009528) Other fixes: - Add basic check that Node.js loads successfully to spec file - New upstream LTS release 6.9.3 * build: shared library support is now working for AIX builds * deps/npm: upgrade npm to 3.10.10 * deps/V8: destructuring of arrow function arguments via computed property no longer throws * inspector: /json/version returns object, not an object wrapped in an array * module: using --debug-brk and --eval together now works as expected * process: improve performance of nextTick up to 20% * repl: the division operator will no longer be accidentally parsed as regex * repl: improved support for generator functions * timers: recanceling a cancelled timers will no longer throw - New upstream LTS version 6.9.2
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1009528
- https://bugzilla.suse.com/1022085
- https://bugzilla.suse.com/1022086
- https://www.suse.com/security/cve/CVE-2016-7055
- https://www.suse.com/security/cve/CVE-2017-3731
- https://www.suse.com/security/cve/CVE-2017-3732
- https://www.suse.com/support/update/announcement/2017/suse-su-20170431-1/