Bug 8201 - Important security upgrades for node.js
Summary: Important security upgrades for node.js
Status: RESOLVED FIXED
Alias: None
Product: buildroot
Classification: Unclassified
Component: Outdated package (show other bugs)
Version: unspecified
Hardware: All All
: P5 critical
Target Milestone: ---
Assignee: Yann E. MORIN
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-07-05 11:09 UTC by Chris
Modified: 2015-07-06 22:08 UTC (History)
2 users (show)

See Also:
Host:
Target:
Build:


Attachments
Important security upgrades for node.js (upgrade to v0.12.6) (17.78 KB, patch)
2015-07-05 14:35 UTC, Chris
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Chris 2015-07-05 11:09:40 UTC
version 0.10.5 is impacted and should be upgraded to 0.10.6.

https://medium.com/@iojs/important-security-upgrades-for-node-js-and-io-js-8ac14ece5852
Comment 1 Thomas Petazzoni 2015-07-05 12:41:11 UTC
I believe there's a mistake in your bug report: it is really 0.12.6 that has been released as a security fix for 0.12.5.

Can you submit a patch to update to 0.12.6 ? Thanks!
Comment 2 Chris 2015-07-05 14:35:50 UTC
Created attachment 6091 [details]
Important security upgrades for node.js (upgrade to v0.12.6)
Comment 3 Chris 2015-07-05 14:39:58 UTC
Hi Thomas,
Can you check and test it ?
Comment 4 Yann E. MORIN 2015-07-05 14:46:13 UTC
Chris,

Thanks for the patch!

The normal process for submitting patches isa to send them to the list,
like explained in the manual:
    http://buildroot.net/downloads/manual/manual.html#submitting-patches

However, I can already spot some issues with the patch: when you use
git-send-email, use the -C option, so that files that are only renamed
(or moved to another directory) only appear as a git rename, please?

Regards,
Yann E. MORIN.
Comment 5 Thomas Petazzoni 2015-07-05 15:18:13 UTC
Yann: we did a mistake when merging the alternate version stuff for NodeJS. The naming of the option should not be 0_12_5, but just 0_12. Otherwise, everytime we upgrade the minor version of NodeJS, we would need to change the Config.in option name, which isn't good. I did not notice that when applying the patches.
Comment 6 Yann E. MORIN 2015-07-05 17:00:03 UTC
Thomas, 

Yes, probably. And also for 0_10, I guess.

Regards,
Yann E. MORIN.
Comment 7 Yann E. MORIN 2015-07-06 22:08:52 UTC
Chris,

We believe this has been fixed with:
    781529b package/nodejs: security bump
    http://git.buildroot.org/buildroot/commit/?id=781529b159313c04903791c6f9e437e697f0e3a9

Regards,
Yann E. MORIN.