diff options
author | Myles Borins <mylesborins@google.com> | 2017-07-10 16:16:01 +0100 |
---|---|---|
committer | Myles Borins <mylesborins@google.com> | 2017-07-11 17:50:09 +0100 |
commit | 6218939cdd0e10e2a614728a8da3f27c7296ec57 (patch) | |
tree | 08af755d3a81353ce286d4646676523eb457d902 /CHANGELOG.md | |
parent | 0130cf55bb957ae4409cd58f8f380f83bf0f6acc (diff) | |
download | android-node-v8-6218939cdd0e10e2a614728a8da3f27c7296ec57.tar.gz android-node-v8-6218939cdd0e10e2a614728a8da3f27c7296ec57.tar.bz2 android-node-v8-6218939cdd0e10e2a614728a8da3f27c7296ec57.zip |
2017-07-11, Version 6.11.1 'Boron' (LTS)
This is a security release. All Node.js users should consult the
security release summary at:
https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/
for details on patched vulnerabilities.
Notable Changes:
* build:
- Disable V8 snapshots - The hashseed embedded in the snapshot is
currently the same for all runs of the binary. This opens node
up to collision attacks which could result in a Denial of Service.
We have temporarily disabled snapshots until a more robust solution
is found (Ali Ijaz Sheikh)
* deps:
- CVE-2017-1000381 - The c-ares function ares_parse_naptr_reply(),
which is used for parsing NAPTR responses, could be triggered to
read memory outside of the given input buffer if the passed in DNS
response packet was crafted in a particular way. This patch checks
that there is enough data for the required elements of an NAPTR
record (2 int16, 3 bytes for string lengths) before processing a
record. (David Drysdale)
PR-URL: https://github.com/nodejs/node-private/pull/89
Diffstat (limited to 'CHANGELOG.md')
-rw-r--r-- | CHANGELOG.md | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index 4f2a75d5b8..c772c459d2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -52,7 +52,8 @@ release. <a href="doc/changelogs/CHANGELOG_V7.md#7.0.0">7.0.0</a><br/> </td> <td valign="top"> -<b><a href="doc/changelogs/CHANGELOG_V6.md#6.11.0">6.11.0</a></b><br/> +<b><a href="doc/changelogs/CHANGELOG_V6.md#6.11.1">6.11.1</a></b><br/> +<a href="doc/changelogs/CHANGELOG_V6.md#6.11.0">6.11.0</a><br/> <a href="doc/changelogs/CHANGELOG_V6.md#6.10.3">6.10.3</a><br/> <a href="doc/changelogs/CHANGELOG_V6.md#6.10.2">6.10.2</a><br/> <a href="doc/changelogs/CHANGELOG_V6.md#6.10.1">6.10.1</a><br/> |