summaryrefslogtreecommitdiff
path: root/lib/_stream_readable.js
diff options
context:
space:
mode:
authorRod Vagg <rod@vagg.org>2019-02-28 16:58:49 +1100
committerRod Vagg <rod@vagg.org>2019-02-28 22:36:11 +1100
commit0d64a560121e7420df9df7c2b5a7e162c4ef307b (patch)
treecab8a98ed9d024dbc2b143d6369a5aa423072ca2 /lib/_stream_readable.js
parent980cce6d29e39bd6d2f86d4f7d25360a4dc2ccc3 (diff)
downloadandroid-node-v8-0d64a560121e7420df9df7c2b5a7e162c4ef307b.tar.gz
android-node-v8-0d64a560121e7420df9df7c2b5a7e162c4ef307b.tar.bz2
android-node-v8-0d64a560121e7420df9df7c2b5a7e162c4ef307b.zip
2019-02-28, Version 6.17.0 'Boron' (LTS)
This is a security release. All Node.js users should consult the security release summary at: https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/ for details on patched vulnerabilities. Fixes for the following CVEs are included in this release: * Node.js: Denial of Service with keep-alive HTTP connections (CVE-2019-5739) * Node.js: Slowloris HTTP Denial of Service with keep-alive (CVE-2019-5737) * OpenSSL: 0-byte record padding oracle (CVE-2019-1559) Notable Changes: * deps: OpenSSL has been upgraded to 1.0.2r which contains a fix for CVE-2019-1559 (https://www.openssl.org/news/secadv/20190226.txt). Under certain circumstances, a TLS server can be forced to respond differently to a client if a zero-byte record is received with an invalid padding compared to a zero-byte record with an invalid MAC. This can be used as the basis of a padding oracle attack to decrypt data. * http: - Backport `server.keepAliveTimeout` to prevent keep-alive HTTP and HTTPS connections remaining open and inactive for an extended period of time, leading to a potential Denial of Service (DoS). (CVE-2019-5739 / Timur Shemsedinov, Matteo Collina) - Further prevention of "Slowloris" attacks on HTTP and HTTPS connections by consistently applying the receive timeout set by `server.headersTimeout` to connections in keep-alive mode. Reported by Marco Pracucci (https://voxnest.com). (CVE-2019-5737 / Matteo Collina) PR-URL: https://github.com/nodejs-private/node-private/pull/169
Diffstat (limited to 'lib/_stream_readable.js')
0 files changed, 0 insertions, 0 deletions