package/nodejs: security bump to version 8.14.0
authorPeter Korsgaard <peter@korsgaard.com>
Sun, 9 Dec 2018 22:18:30 +0000 (23:18 +0100)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Mon, 10 Dec 2018 10:47:50 +0000 (11:47 +0100)
commit0de2c9c76cd0a522fc1eb4b8d63bb5070efaecd3
treeaa8ee2c8fb719ef11caa7f46584fe70f0d872bc4
parente273c36ad086189c081a41f2de7966348e085e37
package/nodejs: security bump to version 8.14.0

Fixes the following security vulnerabilities:

- Node.js: Denial of Service with large HTTP headers (CVE-2018-12121)
- Node.js: Slowloris HTTP Denial of Service (CVE-2018-12122 / Node.js)
- Node.js: Hostname spoofing in URL parser for javascript protocol
  (CVE-2018-12123)
- Node.js: HTTP request splitting (CVE-2018-12116)
- OpenSSL: Timing vulnerability in DSA signature generation (CVE-2018-0734)
- OpenSSL: Microarchitecture timing vulnerability in ECC scalar
  multiplication (CVE-2018-5407)

For more details, see the announcement:
https://nodejs.org/en/blog/release/v8.14.0/

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/nodejs/nodejs.hash
package/nodejs/nodejs.mk