Skip to content

Release proposal: v0.12.17 - #9147

Merged
rvagg merged 3 commits into
nodejs:v0.12from
rvagg:v0.12.17-proposal
Oct 18, 2016
Merged

Release proposal: v0.12.17#9147
rvagg merged 3 commits into
nodejs:v0.12from
rvagg:v0.12.17-proposal

Conversation

@rvagg

Copy link
Copy Markdown
Member

2016-10-18, Version 0.12.17 (Maintenance), @rvagg

This is a security release. All Node.js users should consult the security release summary at https://nodejs.org/en/blog/vulnerability/october-2016-security-releases/ for details on patched vulnerabilities.

Notable changes:

Commits:

Incorrect string length calculation when passing escaped dot.
- CVE: CVE-2016-5180
- Upstream bug: https://c-ares.haxx.se/adv_20160929.html
Ref: nodejs#9037
PR-URL: nodejs#8849
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Reviewed-By: Fedor Indutny <fedor.indutny@gmail.com>
@nodejs-github-botnodejs-github-bot added cares Issues and PRs related to the c-ares dependency or the cares_wrap binding. v0.12 labels Oct 18, 2016
@rvagg

Copy link
Copy Markdown
MemberAuthor

@rvagg

Copy link
Copy Markdown
MemberAuthor

PR-URL: nodejs#9155
Reviewed-By: Johan Bergström <bugs@bergstroem.nu>
Reviewed-By: João Reis <reis@janeasystems.com>
This is a security release. All Node.js users should consult the
security release summary at
https://nodejs.org/en/blog/vulnerability/october-2016-security-releases/
for details on patched vulnerabilities.
Notable changes:
* c-ares: fix for single-byte buffer overwrite, CVE-2016-5180, more
information at https://c-ares.haxx.se/adv_20160929.html
(Daniel Stenberg)
PR-URL: nodejs#9147
@rvagg
rvagg merged commit 1da5ccf into nodejs:v0.12Oct 18, 2016
rvagg added a commit that referenced this pull request Oct 18, 2016
This is a security release. All Node.js users should consult the
security release summary at
https://nodejs.org/en/blog/vulnerability/october-2016-security-releases/
for details on patched vulnerabilities.
Notable changes:
* c-ares: fix for single-byte buffer overwrite, CVE-2016-5180, more
information at https://c-ares.haxx.se/adv_20160929.html
(Daniel Stenberg)
PR-URL: #9147
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

caresIssues and PRs related to the c-ares dependency or the cares_wrap binding.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@rvagg@nodejs-github-bot@bagder