주요 변경사항
보안 릴리스입니다.
다음 취약점이 수정되었습니다.
- CVE-2020-8172: TLS 세션 재사용으로 인해 호스트 인증서 확인 과정이 우회될 수 있었던 문제 (높음).
- CVE-2020-11080: HTTP/2 대용량 SETTINGS 프레임 서비스 거부 공격 (낮음).
- CVE-2020-8174:
napi_get_value_string_*()
이 다양한 메모리 오염을 허용하던 문제 (높음).
Commits
- [
c6d0bdacc4
] - crypto: update root certificates (AshCripps) #33682 - [
916b2824d1
] - (SEMVER-MINOR) deps: update nghttp2 to 1.41.0 (James M Snell) nodejs-private/node-private#206 - [
d381426377
] - (SEMVER-MINOR) http2: implement support for max settings entries (James M Snell) nodejs-private/node-private#206 - [
7dd8982570
] - napi: fix memory corruption vulnerability (Tobias Nießen) nodejs-private/node-private#195 - [
0932309af2
] - tls: emitsession
after verifying certificate (Fedor Indutny) nodejs-private/node-private#200 - [
c392d3923f
] - tools: update certdata.txt (AshCripps) #33682
Windows 32-bit Installer: https://nodejs.org/dist/v12.18.0/node-v12.18.0-x86.msi
Windows 64-bit Installer: https://nodejs.org/dist/v12.18.0/node-v12.18.0-x64.msi
Windows 32-bit Binary: https://nodejs.org/dist/v12.18.0/win-x86/node.exe
Windows 64-bit Binary: https://nodejs.org/dist/v12.18.0/win-x64/node.exe
macOS 64-bit Installer: https://nodejs.org/dist/v12.18.0/node-v12.18.0.pkg
macOS 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-darwin-x64.tar.gz
Linux 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-linux-x64.tar.xz
Linux PPC LE 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-linux-ppc64le.tar.xz
Linux s390x 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-linux-s390x.tar.xz
AIX 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-aix-ppc64.tar.gz
SmartOS 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-sunos-x64.tar.xz
ARMv7 32-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-linux-armv7l.tar.xz
ARMv8 64-bit Binary: https://nodejs.org/dist/v12.18.0/node-v12.18.0-linux-arm64.tar.xz
Source Code: https://nodejs.org/dist/v12.18.0/node-v12.18.0.tar.gz
Other release files: https://nodejs.org/dist/v12.18.0/
Documentation: https://nodejs.org/docs/v12.18.0/api/
SHASUMS
1 | -----BEGIN PGP SIGNED MESSAGE----- |