nodejs (4.2.6~dfsg-1ubuntu4.2) xenial-security; urgency=medium
* SECURITY UPDATE: CRLF injection vulnerability
- debian/patches/CVE-2016-5325-1.patch: Previously, the reason argument
passed to ServerResponse#writeHead was not being properly validated. One
could pass CRLFs which could lead to http response splitting. This
commit changes the behavior to throw an error in the event any invalid
characters are included in the reason.
- debian/patches/CVE-2016-5325-2.patch: The certificates in test fixtures
were set to expire in 999 days since they were generated. That time has
passed, and they have to be reissued. Bump expiration time to 99999 days
for all of them to prevent this from happening again in near future.
-- Mike Salvatore <email address hidden> Wed, 08 Aug 2018 10:16:51 -0400
debug symbols for package nodejs
debug symbols for package nodejs-dev