Opened 3 weeks ago

Closed 9 days ago

#19638 closed enhancement (fixed)

node.js-20.12.2

Reported by: Bruce Dubbs Owned by: Rahul Chandra
Priority: elevated Milestone: 12.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Rahul Chandra, 3 weeks ago

Owner: changed from blfs-book to Rahul Chandra
Status: newassigned

comment:2 by Rahul Chandra, 9 days ago

2024-04-10, Version 20.12.2 'Iron' (LTS), @RafaelGSS

This is a security release.
Notable Changes

    CVE-2024-27980 - Command injection via args parameter of child_process.spawn without shell option enabled on Windows

Commits

    [69ffc6d50d] - src: disallow direct .bat and .cmd file spawning (Ben Noordhuis) nodejs-private/node-private#563

Windows 32-bit Installer: https://nodejs.org/dist/v20.12.2/node-v20.12.2-x86.msi
Windows 64-bit Installer: https://nodejs.org/dist/v20.12.2/node-v20.12.2-x64.msi
Windows ARM 64-bit Installer: https://nodejs.org/dist/v20.12.2/node-v20.12.2-arm64.msi
Windows 32-bit Binary: https://nodejs.org/dist/v20.12.2/win-x86/node.exe
Windows 64-bit Binary: https://nodejs.org/dist/v20.12.2/win-x64/node.exe
Windows ARM 64-bit Binary: https://nodejs.org/dist/v20.12.2/win-arm64/node.exe
macOS 64-bit Installer: https://nodejs.org/dist/v20.12.2/node-v20.12.2.pkg
macOS Apple Silicon 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-darwin-arm64.tar.gz
macOS Intel 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-darwin-x64.tar.gz
Linux 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-linux-x64.tar.xz
Linux PPC LE 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-linux-ppc64le.tar.xz
Linux s390x 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-linux-s390x.tar.xz
AIX 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-aix-ppc64.tar.gz
ARMv7 32-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-linux-armv7l.tar.xz
ARMv8 64-bit Binary: https://nodejs.org/dist/v20.12.2/node-v20.12.2-linux-arm64.tar.xz
Source Code: https://nodejs.org/dist/v20.12.2/node-v20.12.2.tar.gz
Other release files: https://nodejs.org/dist/v20.12.2/
Documentation: https://nodejs.org/docs/v20.12.2/api/

comment:3 by Rahul Chandra, 9 days ago

The only CVE is for windows, but I'll file an SA regardless

comment:4 by Rahul Chandra, 9 days ago

Priority: normalelevated

comment:5 by Rahul Chandra, 9 days ago

Resolution: fixed
Status: assignedclosed
Fixed @
158956b25cedeec3e5e4b1d3c8efdfe12a95f7b3 - Update to power-profiles-daemon-0.21
76c32349ac4c7874b37e554a44de65a866acd0c8 - Update to mesa-24.0.5
85171f7b4946a514b9b8c34d7e5b03d464356b40 - Update to nodejs-20.12.2
Note: See TracTickets for help on using tickets.