Opened 6 months ago

Closed 6 months ago

#18733 closed enhancement (fixed)

node.js-18.18.2

Reported by: Bruce Dubbs Owned by: ken@…
Priority: normal Milestone: 12.1
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version.

Attachments (1)

node-v18.18.2-python_3.12-1.patch (994 bytes ) - added by martyj19 6 months ago.

Download all attachments as: .zip

Change History (8)

by martyj19, 6 months ago

comment:1 by martyj19, 6 months ago

Needs a slight adjustment to accept Python 3.12. With this change, it does build.

comment:2 by Bruce Dubbs, 6 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: newassigned

comment:3 by Bruce Dubbs, 6 months ago

Resolution: fixed
Status: assignedclosed

Fixed at commits

a149290653 Update to node.js-18.18.2
73ac81bdd4 Add a fix for node-js if Python-3.12 is installed
a768ca48ac Update to xfconf-4.18.2.
5bc7f94afd Update to libsigc++-2.12.1.
f1baf8d6ae Update to harfbuzz-8.2.2.

comment:4 by ken@…, 6 months ago

Resolution: fixed
Status: closedreopened

from https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V18.md#18.18.2

The following CVEs are fixed in this release:

CVE-2023-44487: nghttp2 Security Release (High)

CVE-2023-45143: undici Security Release (High)

CVE-2023-38552: Integrity checks according to policies can be circumvented (Medium)

CVE-2023-39333: Code injection via WebAssembly export names (Low)

Details of these, and other CVEs fixed in v20.8.1 at https://nodejs.org/en/blog/vulnerability/october-2023-security-releases

The first of those was fixed by updating the shipped nghttp2 to v1.57.0, so does not apply to BLFS IFF system nghttpd is used.

Reopening to belatedly flag as a security update and to raise an advisory.

comment:5 by ken@…, 6 months ago

Owner: changed from Bruce Dubbs to ken@…
Status: reopenednew

comment:6 by ken@…, 6 months ago

SA 12.0 026 created.

Something breaks the xml validation, for hte moment I cannot spot where.

comment:7 by ken@…, 6 months ago

Resolution: fixed
Status: newclosed

Error was in an older advisory.

Note: See TracTickets for help on using tickets.