diff options
author | Evan Lucas <evanlucas@me.com> | 2017-07-10 10:33:59 -0500 |
---|---|---|
committer | Evan Lucas <evanlucas@me.com> | 2017-07-11 11:57:37 -0500 |
commit | 22889347dfe5315fe03abb9a4263c30cdd74b436 (patch) | |
tree | f52b57c3956759302e0926ea010df434deeead09 /CHANGELOG.md | |
parent | 89e121d4a7765972b7f52c9503864120d93ec504 (diff) | |
download | android-node-v8-22889347dfe5315fe03abb9a4263c30cdd74b436.tar.gz android-node-v8-22889347dfe5315fe03abb9a4263c30cdd74b436.tar.bz2 android-node-v8-22889347dfe5315fe03abb9a4263c30cdd74b436.zip |
2017-07-11, Version 8.1.4 (Current)
This is a security release. All Node.js users should consult the
security release summary at
https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/
for details on patched vulnerabilities.
Notable changes
* **build**:
- Disable V8 snapshots - The hashseed embedded in the snapshot is
currently the same for all runs of the binary. This opens node up to
collision attacks which could result in a Denial of Service. We have
temporarily disabled snapshots until a more robust solution is found
(Ali Ijaz Sheikh)
* **deps**:
- CVE-2017-1000381 - The c-ares function ares_parse_naptr_reply(),
which is used for parsing NAPTR responses, could be triggered to
read memory outside of the given input buffer if the passed in DNS
response packet was crafted in a particular way. This patch checks that
there is enough data for the required elements of an NAPTR record (2
int16, 3 bytes for string lengths) before processing a record. (David
Drysdale)
PR-URL: https://github.com/nodejs/node-private/pull/91
Diffstat (limited to 'CHANGELOG.md')
-rw-r--r-- | CHANGELOG.md | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index c07a5e01ce..c5020ae1d9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -27,7 +27,8 @@ release. </tr> <tr> <td valign="top"> -<b><a href="doc/changelogs/CHANGELOG_V8.md#8.1.3">8.1.3</a></b><br/> +<b><a href="doc/changelogs/CHANGELOG_V8.md#8.1.4">8.1.4</a></b><br/> +<a href="doc/changelogs/CHANGELOG_V8.md#8.1.3">8.1.3</a><br/> <a href="doc/changelogs/CHANGELOG_V8.md#8.1.2">8.1.2</a><br/> <a href="doc/changelogs/CHANGELOG_V8.md#8.1.1">8.1.1</a><br/> <a href="doc/changelogs/CHANGELOG_V8.md#8.1.0">8.1.0</a><br/> |