ELSA-2020-0579

ELSA-2020-0579 - nodejs:10 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2020-02-26

Description


nodejs
[1:10.19.0-1]
- Rebase to 10.19.0 to fix CVE-2019-15604 to CVE-2019-15606

[1:10.16.3-1]
- Rebase to 10.16.3 to fix CVE-2019-9511 to CVE-2019-9518

[1:10.14.1-1]
- Resolves: RHBZ#1644207
- fixes node-gyp permissions
- rebase

[1:10.11.0-2]
- BuildRequire nodejs-packaging for proper npm dependency generation
- Resolves: rhbz#1615947

[1:10.11.0-1]
- Rebase to 10.11.0
- Import changes from fedora
- Resolves: rhbz#1621766

[1:10.7.0-5]
- Import sources from fedora
- Allow using python2 at %build and %install
- turn off debug for aarch64

[1:10.7.0-4]
- Fix npm upgrade scriptlet
- Fix unexpected trailing .1 in npm release field

[1:10.7.0-3]
- Restore annotations to binaries
- Fix unexpected trailing .1 in release field

[1:10.7.0-2]
- Update to 10.7.0
- https://nodejs.org/en/blog/release/v10.7.0/
- https://nodejs.org/en/blog/release/v10.6.0/

[1:10.5.0-1.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

[1:10.5.0-1]
- Update to 10.5.0
- https://nodejs.org/en/blog/release/v10.5.0/

[1:10.4.1-1]
- Update to 10.4.1 to address security issues
- https://nodejs.org/en/blog/release/v10.4.1/
- Resolves: rhbz#1590801
- Resolves: rhbz#1591014
- Resolves: rhbz#1591019

[1:10.4.0-1]
- Update to 10.4.0
- https://nodejs.org/en/blog/release/v10.4.0/

[1:10.3.0-1]
- Update to 10.3.0
- Update npm to 6.1.0
- https://nodejs.org/en/blog/release/v10.3.0/

[1:10.2.1-2]
- Fix up bare 'python' to be python2
- Drop redundant entry in docs section

[1:10.2.1-1]
- Update to 10.2.1
- https://nodejs.org/en/blog/release/v10.2.1/

[1:10.2.0-1]
- Update to 10.2.0
- https://nodejs.org/en/blog/release/v10.2.0/

[1:10.1.0-3]
- Fix incorrect rpm macro

[1:10.1.0-2]
- Include upstream v8 fix for ppc64[le]
- Disable debug build on ppc64[le] and s390x

[1:10.1.0-1]
- Update to 10.1.0
- https://nodejs.org/en/blog/release/v10.1.0/
- Reenable node_g binary

[1:10.0.0-1]
- Update to 10.0.0
- https://nodejs.org/en/blog/release/v10.0.0/
- Drop workaround patch
- Temporarily drop node_g binary due to
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85587

[1:9.11.1-2]
- Use standard Fedora linker flags (bug #1543859)

[1:9.11.1-1]
- Update to 9.11.1
- https://nodejs.org/en/blog/release/v9.11.0/
- https://nodejs.org/en/blog/release/v9.11.1/

[1:9.10.0-1]
- Update to 9.10.0
- https://nodejs.org/en/blog/release/v9.10.0/

[1:9.9.0-1]
- Update to 9.9.0
- https://nodejs.org/en/blog/release/v9.9.0/

[1:9.8.0-1]
- Update to 9.8.0
- https://nodejs.org/en/blog/release/v9.8.0/

[1:9.7.0-1]
- Update to 9.7.0
- https://nodejs.org/en/blog/release/v9.7.0/
- Work around F28 build issue

[1:9.6.1-1]
- Update to 9.6.1
- https://nodejs.org/en/blog/release/v9.6.1/
- https://nodejs.org/en/blog/release/v9.6.0/

[1:9.5.0-1]
- Package Node.js 9.5.0

[1:8.9.4-2]
- Fix incorrect Requires:

[1:8.9.4-1]
- Update to 8.9.4
- https://nodejs.org/en/blog/release/v8.9.4/
- Switch to system copy of nghttp2

[1:8.9.3-2]
- Update to 8.9.3
- https://nodejs.org/en/blog/release/v8.9.3/
- https://nodejs.org/en/blog/release/v8.9.2/

[1:8.9.1-2]
- Rebuild for ICU 60.1

[1:8.9.1-1]
- Update to 8.9.1

[1:8.9.0-1]
- Update to 8.9.0
- Drop upstreamed patch

[1:8.8.1-1]
- Update to 8.8.1 to fix a regression

[1:8.8.0-1]
- Security update to 8.8.0
- https://nodejs.org/en/blog/release/v8.8.0/

[1:8.7.0-1]
- Update to 8.7.0
- https://nodejs.org/en/blog/release/v8.7.0/

[1:8.6.0-2]
- Use bcond macro instead of bootstrap conditional

[1:8.6.0-1]
- Fix nghttp2 version
- Update to 8.6.0
- https://nodejs.org/en/blog/release/v8.6.0/

[1:8.5.0-3]
- Build with bootstrap + bundle libuv for modularity
- backport patch for aarch64 debug build

[1:8.5.0-2]
- Disable debug builds on aarch64 due to https://github.com/nodejs/node/issues/15395

[1:8.5.0-1]
- Update to v8.5.0
- https://nodejs.org/en/blog/release/v8.5.0/

[1:8.4.0-2]
- Refactor openssl BR

[1:8.4.0-1]
- Update to v8.4.0
- https://nodejs.org/en/blog/release/v8.4.0/
- http2 is now supported, add bundled nghttp2
- remove openssl 1.0.1 patches, we won't be using them in fedora

[1:8.3.0-1]
- Update to v8.3.0
- https://nodejs.org/en/blog/release/v8.3.0/
- update V8 to 6.0
- update minimal gcc and g++ requirements to 4.9.4

[1:8.2.1-2]
- Bump release to fix broken dependencies

[1:8.2.1-1.2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

[1:8.2.1-1.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild

[1:8.2.1-1]
- Update to v8.2.1
- https://nodejs.org/en/blog/release/v8.2.1/

[1:8.2.0-1]
- Update to v8.2.0
- https://nodejs.org/en/blog/release/v8.2.0/
- Update npm to 5.3.0
- Adds npx command

[1:8.1.4-3]
- s/BuildRequires/Requires/ for http-parser-devel%{?_isa}

[1:8.1.4-2]
- Rename python-devel to python2-devel
- own %{_pkgdocdir}/npm

[1:8.1.4-1]
- Update to v8.1.4
- https://nodejs.org/en/blog/release/v8.1.4/
- Drop upstreamed c-ares patch

[1:8.1.3-1]
- Update to v8.1.3
- https://nodejs.org/en/blog/release/v8.1.3/

[1:8.1.2-1]
- Update to v8.1.2
- remove GCC 7 patch, as it is now fixed in node >= 6.12

nodejs-nodemon
nodejs-packaging


Related CVEs


CVE-2019-15604
CVE-2019-15605
CVE-2019-15606
CVE-2019-16776
CVE-2019-16775
CVE-2019-16777

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) nodejs-10.19.0-1.module+el8.1.0+5552+3cab52c0.src.rpm419c8b6b62fde875e2e7a8cf1c2b68b32bb9d6879bd005725e6e69c06869a967-ol8_aarch64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.src.rpm94ebbb720c4e1dd09d6547194500d3242b4f8b31a718223d57891a6d4cfa1228-ol8_aarch64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.src.rpm94ebbb720c4e1dd09d6547194500d3242b4f8b31a718223d57891a6d4cfa1228-ol8_aarch64_appstream_developer
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.src.rpm1541accb9908963d05364b9a40f2ee31e901ae52ef159d841eeeb3ea409b98a2-ol8_aarch64_appstream
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.src.rpm1541accb9908963d05364b9a40f2ee31e901ae52ef159d841eeeb3ea409b98a2-ol8_aarch64_appstream_developer
nodejs-10.19.0-1.module+el8.1.0+5552+3cab52c0.aarch64.rpm2cd8c5a55d37140ce6cfd40a8e9a49c91052ead599e60cc25c1ad3484c7dd45d-ol8_aarch64_appstream
nodejs-devel-10.19.0-1.module+el8.1.0+5552+3cab52c0.aarch64.rpm853a7710f3b52990806e25f6ce9bb89d8706051f846c94d93036996fa2ee3234-ol8_aarch64_appstream
nodejs-docs-10.19.0-1.module+el8.1.0+5552+3cab52c0.noarch.rpm3eb469794be7bfd31d7b3d9147e9d3ee2281896875fb9189916e66ddc44423d3-ol8_aarch64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.noarch.rpm6e9d8c1ca679bf5776e850475138dfa4b009e8dd8d6cbe7d6072138017fffdf7-ol8_aarch64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.noarch.rpm6e9d8c1ca679bf5776e850475138dfa4b009e8dd8d6cbe7d6072138017fffdf7-ol8_aarch64_appstream_developer
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.noarch.rpm84404ab9b8c409be52b035b546018d4f1cf7f480e5a9681a68d9cbda7aa220dd-ol8_aarch64_appstream
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.noarch.rpm84404ab9b8c409be52b035b546018d4f1cf7f480e5a9681a68d9cbda7aa220dd-ol8_aarch64_appstream_developer
npm-6.13.4-1.10.19.0.1.module+el8.1.0+5552+3cab52c0.aarch64.rpm069fbc212e218c3479f784be53f0179e1ff67569a8d48a54512273442d40c132-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) nodejs-10.19.0-1.module+el8.1.0+5552+3cab52c0.src.rpm419c8b6b62fde875e2e7a8cf1c2b68b32bb9d6879bd005725e6e69c06869a967-ol8_x86_64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.src.rpm94ebbb720c4e1dd09d6547194500d3242b4f8b31a718223d57891a6d4cfa1228-ol8_x86_64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.src.rpm94ebbb720c4e1dd09d6547194500d3242b4f8b31a718223d57891a6d4cfa1228-ol8_x86_64_appstream_developer
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.src.rpm1541accb9908963d05364b9a40f2ee31e901ae52ef159d841eeeb3ea409b98a2-ol8_x86_64_appstream
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.src.rpm1541accb9908963d05364b9a40f2ee31e901ae52ef159d841eeeb3ea409b98a2-ol8_x86_64_appstream_developer
nodejs-10.19.0-1.module+el8.1.0+5552+3cab52c0.x86_64.rpm60534afd723ae1f8fc5bd8e2537feb7fd577e935d8a0e9a55cafa012baa42633-ol8_x86_64_appstream
nodejs-devel-10.19.0-1.module+el8.1.0+5552+3cab52c0.x86_64.rpm35ab423e5a9fa10a8caa693a7aa92f0e934a5e43c081b13b5c810ae216d38dbd-ol8_x86_64_appstream
nodejs-docs-10.19.0-1.module+el8.1.0+5552+3cab52c0.noarch.rpm3eb469794be7bfd31d7b3d9147e9d3ee2281896875fb9189916e66ddc44423d3-ol8_x86_64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.noarch.rpm6e9d8c1ca679bf5776e850475138dfa4b009e8dd8d6cbe7d6072138017fffdf7-ol8_x86_64_appstream
nodejs-nodemon-1.18.3-1.module+el8.1.0+5392+4d6b561f.noarch.rpm6e9d8c1ca679bf5776e850475138dfa4b009e8dd8d6cbe7d6072138017fffdf7-ol8_x86_64_appstream_developer
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.noarch.rpm84404ab9b8c409be52b035b546018d4f1cf7f480e5a9681a68d9cbda7aa220dd-ol8_x86_64_appstream
nodejs-packaging-17-3.module+el8.1.0+5392+4d6b561f.noarch.rpm84404ab9b8c409be52b035b546018d4f1cf7f480e5a9681a68d9cbda7aa220dd-ol8_x86_64_appstream_developer
npm-6.13.4-1.10.19.0.1.module+el8.1.0+5552+3cab52c0.x86_64.rpmb8e83e44da0687dea526b6a68af4afb4e9abfbf8f64fb21b32c9a2a2c75baf46-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete