红联Linux门户
Linux帮助

Node v5.1.1/v4.2.3/v0.12.9/v0.10.41发布

发布时间:2015-12-04 14:54:14来源:红联作者:empast
Node v5.1.1 (Stable),该版本是重要安全更新发布,主要更新内容如下:

http: Fix a bug where an HTTP socket may no longer have an associated parser but a pipelined request triggers a pause or resume, a potential denial-of-service vector. (Fedor Indutny)

openssl: Upgrade to 1.0.2e, containing fixes for:

CVE-2015-3193 "BN_mod_exp may produce incorrect results on x86_64", an attack may be feasible against a Node.js TLS server using DHE key exchange. Details are available at http://openssl.org/news/secadv/20151203.txt.

CVE-2015-3194 "Certificate verify crash with missing PSS parameter", a potential denial-of-service vector for Node.js TLS servers using client authentication; TLS clients are also impacted. Details are available at http://openssl.org/news/secadv/20151203.txt. (Shigeki Ohtsu) #4134

v8: Backport fixes for a bug in JSON.stringify() that can result in out-of-bounds reads for arrays. (Ben Noordhuis)

软件详情:https://nodejs.org/en/blog/release/v5.1.1/

下载地址:https://nodejs.org/

来自:开源中国社区
文章评论

共有 0 条评论