You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa nodejs

Sigurnosni nedostatak programskog paketa nodejs

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2017-11-07 22:23:37.427135

Name : nodejs
Product : Fedora 25
Version : 6.11.5
Release : 1.fc25
Summary : JavaScript runtime
Description :
Node.js is a platform built on Chrome’s JavaScript runtime
for easily building fast, scalable network applications.
Node.js uses an event-driven, non-blocking I/O model that
makes it lightweight and efficient, perfect for data-intensive
real-time applications that run across distributed devices.

Update Information:

# 2017-10-24, Version 6.11.5 ‘Boron’ (LTS), @MylesBorins This is a security
release. All Node.js users should consult the security release summary at for details on patched
vulnerabilities. ## Notable Changes * zlib: * CVE-2017-14919 – In zlib
v1.2.9, a change was made that causes an error to be raised when a raw deflate
stream is initialized with windowBits set to 8. On some versions this crashes
Node and you cannot recover from it, while on some versions it throws an
exception. Node.js will now gracefully set windowBits to 9 replicating the
legacy behavior to avoid a DOS vector. nodejs-private/node-private#95

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade nodejs’ at the command line.
For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list —
To unsubscribe send an email to

AutorTomislav Protega
Cert idNCERT-REF-2017-11-0066-ADV
More in Preporuke
Sigurnosni nedostatak jezgre operacijskog sustava

Otkriven je sigurnosni nedostatak u jezgri operacijskog sustava Fedora. Otkriveni nedostatak posljedica je dereferenciranja NULL pokazivača u funkciji assoc_array_apply_edit(), što...