package/nodejs: security bump to version 8.11.3
authorMartin Bark <martin@barkynet.com>
Sat, 16 Jun 2018 22:44:08 +0000 (23:44 +0100)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sun, 17 Jun 2018 12:04:29 +0000 (14:04 +0200)
commit64baf3def763fe962f19d7ca083cf019a73f6281
treeca369f47b7b4b0cf1191b6d2ba5b3f3cda59091b
parent88813806cb45b5bf50b99f90b9718ccafdfdb63f
package/nodejs: security bump to version 8.11.3

Fixes the following security issues:

- (CVE-2018-7167): Fixes Denial of Service vulnerability where calling
  Buffer.fill() could hang

- (CVE-2018-7161): Fixes Denial of Service vulnerability by updating the
  http2 implementation to not crash under certain circumstances during
  cleanup

- (CVE-2018-1000168): Fixes Denial of Service vulnerability by upgrading
  nghttp2 to 1.32.0

See https://nodejs.org/en/blog/release/v8.11.3/ for more details

Signed-off-by: Martin Bark <martin@barkynet.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/nodejs/nodejs.hash
package/nodejs/nodejs.mk