Node v0.12.9 (LTS)
Rod Vagg
This is an important security release. All Node.js users should consult our December Security Release Summary for details on patched vulnerabilities.
Notable changes(/
- http: Fix a bug where an HTTP socket may no longer have an associated parser but a pipelined request triggers a pause or resume, a potential denial-of-service vector. (Fedor Indutny)
- openssl: Upgrade to 1.0.1q, fixes CVE-2015-3194 "Certificate verify crash with missing PSS parameter", a potential denial-of-service vector for Node.js TLS servers using client authentication; TLS clients are also impacted. Details are available at http://openssl.org/news/secadv/20151203.txt. (Ben Noordhuis) https://github.com/nodejs/node/pull/4133
Commits
- [
8d24a14f2c
] - deps: upgrade to openssl 1.0.1q (Ben Noordhuis) #4133 - [
dfc6f4a9af
] - http: fix pipeline regression (Fedor Indutny)
Windows 32-bit Installer: https://nodejs.org/dist/v0.12.9/node-v0.12.9-x86.msi
Windows 64-bit Installer: https://nodejs.org/dist/v0.12.9/x64/node-v0.12.9-x64.msi
Windows 32-bit Binary: https://nodejs.org/dist/v0.12.9/node.exe
Windows 64-bit Binary: https://nodejs.org/dist/v0.12.9/x64/node.exe
Mac OS X Universal Installer: https://nodejs.org/dist/v0.12.9/node-v0.12.9.pkg
Mac OS X 64-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-darwin-x64.tar.gz
Mac OS X 32-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-darwin-x86.tar.gz
Linux 32-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-linux-x86.tar.gz
Linux 64-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-linux-x64.tar.gz
SmartOS 32-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-sunos-x86.tar.gz
SmartOS 64-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-sunos-x64.tar.gz
Source Code: https://nodejs.org/dist/v0.12.9/node-v0.12.9.tar.gz
Other release files: https://nodejs.org/dist/v0.12.9/
Documentation: https://nodejs.org/docs/v0.12.9/api/
Shasums (GPG signing hash: SHA512, file hash: SHA256):
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
ca0bb8e1a2c1e5c23bbd1f8f6e4859f279532a820767f2a356fafd74c7a96dc9 node.exe
9a197cf39b61dec42fcdccf3b3f6f3289c9720186647d4474e39fa0e575bb0a6 node.exp
3ece6db1d6dc791c414d84324f41d3b3bae6ae57bd1c6185e9fb1802fbc5ef37 node.lib
c8435274e80cdb80cced49ef724f3c53b3f1439eb3b8fca022f0b18b4bcea3b7 node.pdb
8a40582c8f346f4acb08ab29bdc171db5fea55603999e02be1ebfcdd2ed3ca83 node-v0.12.9-darwin-x64.tar.gz
a89d21abe0eaae1fd4cd4753a7ccde5bb60188148742281f1b36830bb02d50fd node-v0.12.9-darwin-x86.tar.gz
0da8dd9dd5bbfa821d4e957a0687f3cc39bc6cbc45f75d6751107142141426ca node-v0.12.9-headers.tar.gz
3416451924c9c996e1d7224f5e5507df84b90dc730d4760e3f4daac1bd4c44df node-v0.12.9-linux-x64.tar.gz
07b25b4a886b1b04d427b2b6414c9e4a913f53bb9574c26f010b35984b70df10 node-v0.12.9-linux-x86.tar.gz
8fa10d973e2dc7296fb5620ddede5a55e87a332762593437ab8db61051045e67 node-v0.12.9.pkg
460a75865d6155dc39794204214c567a239b319122caf116a60f870f0987b720 node-v0.12.9-sunos-x64.tar.gz
039c710094ac76bea7027cf37daceb5708e46cac0bd082d7004c9710ad77ad1f node-v0.12.9-sunos-x86.tar.gz
35daad301191e5f8dd7e5d2fbb711d081b82d1837d59837b8ee224c256cfe5e4 node-v0.12.9.tar.gz
1f57e2fff78519569abced323c6206fc1bd32a1d374c6a05537b2873a88a7928 node-v0.12.9-x86.msi
a765092067696be8b49736b6fce2986350a1c7581be105cf935d85636bbe809e openssl-cli.exe
ee5c379a4a6f5d8640af18d811566b5dacd0ae242e70928114b95825bacd3fd4 openssl-cli.pdb
e8b4a1307332a65c5c699c1b4a4006ffd12f187a3ab9cad8f5d8e2c408a488e6 x64/node.exe
8eb895b612690d8ab2fd06c89d3f289f4e07a9a9292bb9f8cd6c6b8cc09bd05d x64/node.exp
e12d3ae12103ab7d879f4c1f6ac1da77239c73cc4599fe142a7b465837ce23b6 x64/node.lib
a2d7f30af6c1e97e306cc3481e4caa2fa7e8380344acee9f8e25a6121a2df01a x64/node.pdb
0d9913cb6ec8f0ea0cc9718e569a465397884b8a68863e21276866b8d394553f x64/node-v0.12.9-x64.msi
8943965f64d7495c6e8097916558826095472ecf64cd9bdc6ea52bd706aa086f x64/openssl-cli.exe
98ad5e5ff48f486a0844db9398776021c3ba23c384d3a7a2d1229e37563394c2 x64/openssl-cli.pdb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBAgAGBQJWYPz5AAoJEMJzeS99g1RdYvMH/jyTZyBiFjtNrkETy4BlfhMr
LYmB22yTK9wTyb4SNwta1TO8WXOHg9NwH4VVAHXgBrMeIpgV8DJyGjHW2AhibFyB
NohDdcyIbzCciR07AsA9Vqa1u9ZFUNLzH/+5389eIINyhJTUB1gtlKxX/IbQ+luS
+Iy99sEu8RiaOmwus7vsY0agvatm7k8nUOVheQlXUh8OH3nYxqDKzTxdzxJm1j9k
cL0RWYErA5b/LRLeRAHJG9uz81Jd/EiArhe+7FBLTrJVl69Ruk/nPeUrbKR/D2MC
Kjd5mEfYSGwDV9YcGecLDq7CQAhscaBqQyFoynE8dOB46wW2PyV9NkYPC5TP9RE=
=F7h4
-----END PGP SIGNATURE-----