Subject: CVS commit: pkgsrc/lang/nodejs6
From: Filip Hajny
Date: 2017-07-11 21:10:32
Message id: 20170711191032.3488CFACB@cvs.NetBSD.org

Log Message:
Update lang/nodejs6 to 6.11.1.

- Disable V8 snapshots - The hashseed embedded in the snapshot is
  currently the same for all runs of the binary. This opens node up to
  collision attacks which could result in a Denial of Service. We have
  temporarily disabled snapshots until a more robust solution is found
- CVE-2017-1000381 - The c-ares function ares_parse_naptr_reply(), which
  is used for parsing NAPTR responses, could be triggered to read memory
  outside of the given input buffer if the passed in DNS response packet
  was crafted in a particular way. This patch checks that there is
  enough data for the required elements of an NAPTR record (2 int16, 3
  bytes for string lengths) before processing a record.

Files:
RevisionActionfile
1.13modifypkgsrc/lang/nodejs6/Makefile
1.12modifypkgsrc/lang/nodejs6/distinfo