[SECURITY] Fedora EPEL 6 Update: v8-3.14.5.10-14.el6

updates at fedoraproject.org updates at fedoraproject.org
Fri Oct 31 01:27:16 UTC 2014


--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2014-2719
2014-09-24 02:27:57
--------------------------------------------------------------------------------

Name        : v8
Product     : Fedora EPEL 6
Version     : 3.14.5.10
Release     : 14.el6
URL         : http://code.google.com/p/v8
Summary     : JavaScript Engine
Description :
V8 is Google's open source JavaScript engine. V8 is written in C++ and is used
in Google Chrome, the open source browser from Google. V8 implements ECMAScript
as specified in ECMA-262, 3rd edition.

--------------------------------------------------------------------------------
Update Information:

This update provides the latest stable version of Node.js and corresponding backports to the v8 package.

This update resolves CVE-2013-6668, which has only a minor impact since Node.js is not typically used to execute untrusted JavaScript.  For more information on the fixed vulnerability, please see the CVE bugs listed below.

Changes in this update include:

* v8: fix a crash introduced by previous release (Fedor Indutny)
* crypto: use domains for any callback-taking method (Chris Dickinson)
* http: do not send `0rnrn` in TE HEAD responses (Fedor Indutny)
* querystring: fix unescape override (Tristan Berger)
* url: Add support for RFC 3490 separators (Mathias Bynens)
* v8: backport CVE-2013-6668
* cluster: disconnect should not be synchronous (Sam Roberts)
* fs: fix fs.readFileSync fd leak when get RangeError (Jackson Tian)
* stream: fix Readable.wrap objectMode falsy values (James Halliday)
* timers: fix timers with non-integer delay hanging. (Julien Gilli)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1074737 - CVE-2013-6668 v8: multiple vulnerabilities fixed in Google Chrome version 33.0.1750.146
        https://bugzilla.redhat.com/show_bug.cgi?id=1074737
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update v8' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the epel-package-announce mailing list