Node v0.12.9 (LTS)

중요한 보안 릴리스입니다.
Node.js 사용자는 모두 12월 보안 릴리스 요약을 참고하여 패치된 취약점에 관한 자세한 내용을 살펴보기 바랍니다.

주요 변경 사항

  • http: HTTP 소켓에 연결된 파서가 없는데도 파이프라인에 연결된 요청이 일시 정지(pause)나 속행(resume)을 요청하는 잠재적인 서비스 거부(DoS) 벡터가 있던 버그가 수정되었습니다. (Fedor Indutny)
  • openssl: 1.0.1q로 업그레이드.
    클라이언트 인증을 사용하는 Node.js TLS 서버에 서비스 거부를 일으킬 수 있는 잠재적인 벡터, CVE-2015-3194 “PSS 파라미터 누락시 인증서 검증 종료” 문제를 수정합니다. 이 문제점은 TLS 클라이언트도 영향을 받습니다.
    자세한 사항은 http://openssl.org/news/secadv/20151203.txt를 참고하세요. (Ben Noordhuis) https://github.com/nodejs/node/pull/4133

Commits

  • [8d24a14f2c] - deps: upgrade to openssl 1.0.1q (Ben Noordhuis) #4133
  • [dfc6f4a9af] - http: fix pipeline regression (Fedor Indutny)

Windows 32-bit Installer: https://nodejs.org/dist/v0.12.9/node-v0.12.9-x86.msi

Windows 64-bit Installer: https://nodejs.org/dist/v0.12.9/x64/node-v0.12.9-x64.msi

Windows 32-bit Binary: https://nodejs.org/dist/v0.12.9/node.exe

Windows 64-bit Binary: https://nodejs.org/dist/v0.12.9/x64/node.exe

Mac OS X Universal Installer: https://nodejs.org/dist/v0.12.9/node-v0.12.9.pkg

Mac OS X 64-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-darwin-x64.tar.gz

Mac OS X 32-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-darwin-x86.tar.gz

Linux 32-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-linux-x86.tar.gz

Linux 64-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-linux-x64.tar.gz

SmartOS 32-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-sunos-x86.tar.gz

SmartOS 64-bit Binary: https://nodejs.org/dist/v0.12.9/node-v0.12.9-sunos-x64.tar.gz

Source Code: https://nodejs.org/dist/v0.12.9/node-v0.12.9.tar.gz

Other release files: https://nodejs.org/dist/v0.12.9/

Documentation: https://nodejs.org/docs/v0.12.9/api/

Shasums (GPG signing hash: SHA512, file hash: SHA256):

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

ca0bb8e1a2c1e5c23bbd1f8f6e4859f279532a820767f2a356fafd74c7a96dc9 node.exe
9a197cf39b61dec42fcdccf3b3f6f3289c9720186647d4474e39fa0e575bb0a6 node.exp
3ece6db1d6dc791c414d84324f41d3b3bae6ae57bd1c6185e9fb1802fbc5ef37 node.lib
c8435274e80cdb80cced49ef724f3c53b3f1439eb3b8fca022f0b18b4bcea3b7 node.pdb
8a40582c8f346f4acb08ab29bdc171db5fea55603999e02be1ebfcdd2ed3ca83 node-v0.12.9-darwin-x64.tar.gz
a89d21abe0eaae1fd4cd4753a7ccde5bb60188148742281f1b36830bb02d50fd node-v0.12.9-darwin-x86.tar.gz
0da8dd9dd5bbfa821d4e957a0687f3cc39bc6cbc45f75d6751107142141426ca node-v0.12.9-headers.tar.gz
3416451924c9c996e1d7224f5e5507df84b90dc730d4760e3f4daac1bd4c44df node-v0.12.9-linux-x64.tar.gz
07b25b4a886b1b04d427b2b6414c9e4a913f53bb9574c26f010b35984b70df10 node-v0.12.9-linux-x86.tar.gz
8fa10d973e2dc7296fb5620ddede5a55e87a332762593437ab8db61051045e67 node-v0.12.9.pkg
460a75865d6155dc39794204214c567a239b319122caf116a60f870f0987b720 node-v0.12.9-sunos-x64.tar.gz
039c710094ac76bea7027cf37daceb5708e46cac0bd082d7004c9710ad77ad1f node-v0.12.9-sunos-x86.tar.gz
35daad301191e5f8dd7e5d2fbb711d081b82d1837d59837b8ee224c256cfe5e4 node-v0.12.9.tar.gz
1f57e2fff78519569abced323c6206fc1bd32a1d374c6a05537b2873a88a7928 node-v0.12.9-x86.msi
a765092067696be8b49736b6fce2986350a1c7581be105cf935d85636bbe809e openssl-cli.exe
ee5c379a4a6f5d8640af18d811566b5dacd0ae242e70928114b95825bacd3fd4 openssl-cli.pdb
e8b4a1307332a65c5c699c1b4a4006ffd12f187a3ab9cad8f5d8e2c408a488e6 x64/node.exe
8eb895b612690d8ab2fd06c89d3f289f4e07a9a9292bb9f8cd6c6b8cc09bd05d x64/node.exp
e12d3ae12103ab7d879f4c1f6ac1da77239c73cc4599fe142a7b465837ce23b6 x64/node.lib
a2d7f30af6c1e97e306cc3481e4caa2fa7e8380344acee9f8e25a6121a2df01a x64/node.pdb
0d9913cb6ec8f0ea0cc9718e569a465397884b8a68863e21276866b8d394553f x64/node-v0.12.9-x64.msi
8943965f64d7495c6e8097916558826095472ecf64cd9bdc6ea52bd706aa086f x64/openssl-cli.exe
98ad5e5ff48f486a0844db9398776021c3ba23c384d3a7a2d1229e37563394c2 x64/openssl-cli.pdb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJWYPz5AAoJEMJzeS99g1RdYvMH/jyTZyBiFjtNrkETy4BlfhMr
LYmB22yTK9wTyb4SNwta1TO8WXOHg9NwH4VVAHXgBrMeIpgV8DJyGjHW2AhibFyB
NohDdcyIbzCciR07AsA9Vqa1u9ZFUNLzH/+5389eIINyhJTUB1gtlKxX/IbQ+luS
+Iy99sEu8RiaOmwus7vsY0agvatm7k8nUOVheQlXUh8OH3nYxqDKzTxdzxJm1j9k
cL0RWYErA5b/LRLeRAHJG9uz81Jd/EiArhe+7FBLTrJVl69Ruk/nPeUrbKR/D2MC
Kjd5mEfYSGwDV9YcGecLDq7CQAhscaBqQyFoynE8dOB46wW2PyV9NkYPC5TP9RE=
=F7h4
-----END PGP SIGNATURE-----