{"affected":[{"ecosystem_specific":{"binaries":[{"nodejs4":"4.7.3-14.1","nodejs4-devel":"4.7.3-14.1","nodejs4-docs":"4.7.3-14.1","npm4":"4.7.3-14.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Web and Scripting 12","name":"nodejs4","purl":"pkg:rpm/suse/nodejs4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.7.3-14.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"nodejs4":"4.7.3-14.1"}]},"package":{"ecosystem":"SUSE:Enterprise Storage 4","name":"nodejs4","purl":"pkg:rpm/suse/nodejs4&distro=SUSE%20Enterprise%20Storage%204"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.7.3-14.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for nodejs4 fixes the following issues:\n\n- New upstream LTS release 4.7.3\n  The embedded openssl sources were updated to 1.0.2k\n    (CVE-2017-3731, CVE-2017-3732, CVE-2016-7055,\n     bsc#1022085, bsc#1022086, bsc#1009528)\n- No changes in LTS version 4.7.2\n\n- New upstream LTS release 4.7.1\n  * build: shared library support is now working for AIX builds\n  * repl: passing options to the repl will no longer overwrite\n          defaults\n  * timers: recanceling a cancelled timers will no longer throw\n\n- New upstream LTS version 4.7.0\n  * build: introduce the configure --shared option for embedders\n  * debugger: make listen address configurable in debugger server\n  * dgram: generalized send queue to handle close, fixing a\n           potential throw when dgram socket is closed in the\n           listening event handler\n  * http: introduce the 451 status code 'Unavailable For\n          Legal Reasons'\n  * gtest: the test reporter now outputs tap comments as yamlish\n  * tls: introduce secureContext for tls.connect (useful for\n         caching client certificates, key, and CA certificates)\n  * tls: fix memory leak when writing data to TLSWrap instance\n         during handshake\n  * src: node no longer aborts when c-ares initialization fails\n  * ported and updated system CA store for the new node crypto code\n\n- New upstream LTS version 4.6.2\n  * build:\n    + It is now possible to build the documentation from the release tarball.\n  * buffer:\n    + Buffer.alloc() will no longer incorrectly return a zero filled buffer\n      when an encoding is passed.\n  * deps:\n    + Upgrade npm in LTS to 2.15.11.\n  * repl:\n    + Enable tab completion for global properties.\n  * url:\n    + url.format() will now encode all '#' in search.\n\n- Add missing conflicts to base package. It's not possible to have\n  concurrent nodejs installations.\n\n- enable usage of system certificate store on SLE11SP4 by \n  requiring openssl1 (bsc#1000036)\n","id":"SUSE-SU-2017:0855-1","modified":"2017-03-29T11:01:13Z","published":"2017-03-29T11:01:13Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20170855-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1000036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1009528"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3731"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3732"}],"related":["CVE-2016-7055","CVE-2017-3731","CVE-2017-3732"],"summary":"Security update for nodejs4","upstream":["CVE-2016-7055","CVE-2017-3731","CVE-2017-3732"]}