[ubuntu/noble-proposed] nodejs 18.19.1+dfsg-2 (Accepted)

Gianfranco Costamagna costamagnagianfranco at yahoo.it
Wed Feb 21 14:21:27 UTC 2024


nodejs (18.19.1+dfsg-2) unstable; urgency=medium

  [ Bo YU ]
  * Allow more risc64 tests to fail. Closes: #1064331

  [ Jérémy Lal ]
  * Allow more mips64el tests to fail. Closes: #1064306
    Upstream still supports those architectures but they
    take more time to fix corner cases.

nodejs (18.19.1+dfsg-1) unstable; urgency=medium

  * New upstream version 18.19.1. Closes: 1064055.
    + CVE-2024-21892 (High)
      Code injection and privilege escalation through Linux capabilities
    + CVE-2024-22019 (High)
      Reading unprocessed HTTP request with unbounded chunk
      extension allows DoS attacks
    + CVE-2023-46809 (Medium)
      Marvin Attack vulnerability against PKCS#1 v1.5 padding
  * new architecture: loong64, thanks to Shi Pujin  
  * patch:
    + let loong64 have some failing tests
    + more doc for localhost-no-addrconfig
    + allow test-debugger-heap-profiler to fail. Closes: #1059168
    + disable zlib embedding in v8, disable snapshot compression
  * override lintian source warning for zlib brotli test string
  * fix boostrapping of nodejs package:
    + update README.source
    + nodoc: disable bash completion output
    + patch: disable shared builtins when flag
      node-builtin-modules-path is used
  * include permission headers in libnode-dev
  * B-D pkg-config becomes pkgconf

Date: 2024-02-20 16:36:11.093024+00:00
Signed-By: Gianfranco Costamagna <costamagnagianfranco at yahoo.it>
https://launchpad.net/ubuntu/+source/nodejs/18.19.1+dfsg-2
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list