openwrt-packages/lang/node/patches
Hirokazu MORIKAWA 5657f77c09 node: June 20 2023 Security Releases
Update to v16.20.1

The following CVEs are fixed in this release:
* CVE-2023-30581: mainModule.__proto__ Bypass Experimental Policy Mechanism (High)
* CVE-2023-30585: Privilege escalation via Malicious Registry Key manipulation during Node.js installer repair process (Medium)
* CVE-2023-30588: Process interuption due to invalid Public Key information in x509 certificates (Medium)
* CVE-2023-30589: HTTP Request Smuggling via Empty headers separated by CR (Medium)
* CVE-2023-30590: DiffieHellman does not generate keys after setting a private key (Medium)

* OpenSSL Security Releases  (Depends on shared library provided by OpenWrt)
    * OpenSSL security advisory 28th March.
    * OpenSSL security advisory 20th April.
    * OpenSSL security advisory 30th May

* c-ares vulnerabilities:  (Depends on shared library provided by OpenWrt)
    * GHSA-9g78-jv2r-p7vc
    * GHSA-8r8p-23f3-64c2
    * GHSA-54xr-f67r-4pc4
    * GHSA-x6mf-cxr9-8q6v

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
2023-06-21 20:48:54 +08:00
..
003-path.patch node: June 20 2023 Security Releases 2023-06-21 20:48:54 +08:00
004-musl_support.patch node: Major update from v14 to v16 2022-05-22 11:21:36 +02:00
007-fix_host_build_on_macos.patch node: bump to v16.17.0 2022-08-29 12:45:26 +02:00
010-execvp-arg-list-too-long.patch node: bump to v16.17.0 2022-08-29 12:45:26 +02:00
990-delete_unnecessary_libraries_for_host_execute.patch node: bump to v16.20.0 2023-04-03 23:58:35 +08:00
991-v8_zlib_support.patch node: bump to v16.20.0 2023-04-03 23:58:35 +08:00
992-v8_add_include_dirs.patch node: bump to v16.20.0 2023-04-03 23:58:35 +08:00
999-cast_for_mips32.patch node: bump to v16.17.0 2022-08-29 12:45:26 +02:00
999-deps-v8-src-trap-handler-trap-handler.h.patch node: Major update from v14 to v16 2022-05-22 11:21:36 +02:00
999-fix_icu_conflict.patch node: bump to v14.17.0 2021-05-13 13:19:24 +09:00
999-localhost-no-addrconfig.patch node: bump to v16.18.0 2022-10-28 14:11:20 +02:00
999-revert_enable_pointer_authentication_on_arm64.patch node: bump to v16.20.0 2023-04-03 23:58:35 +08:00