Skip to content

deps: float b18162a7c from openssl (CVE-2018-5407) (8.x and 6.x only)

Low severity timing vulnerability in ECC calculations impacting ECDSA and ECDH. This was fixed already in 1.1.0i which we already have but there was a long delay in getting it back in to 1.0.1. They are not releasing a new 1.0.1 specifically for this and I'd expect there to be a delay on a new version because of a shift in development focus.

So this should go into 8.x and 6.x when we do them next.

@nodejs/release @nodejs/crypto

Ref: https://www.openssl.org/news/secadv/20181112.txt

Merge request reports

Loading