{"affected":[{"ecosystem_specific":{"binaries":[{"nodejs6":"6.9.5-7.1","nodejs6-devel":"6.9.5-7.1","nodejs6-docs":"6.9.5-7.1","npm6":"6.9.5-7.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Web and Scripting 12","name":"nodejs6","purl":"pkg:rpm/suse/nodejs6&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.9.5-7.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for nodejs6 fixes the following issues:\n\nNew upstream LTS release 6.9.5.\n\nThe embedded openssl sources were updated to 1.0.2k (CVE-2017-3731, CVE-2017-3732, CVE-2016-7055, bsc#1022085, bsc#1022086, bsc#1009528)\n\nOther fixes:\n- Add basic check that Node.js loads successfully to spec file\n\n- New upstream LTS release 6.9.3\n  * build: shared library support is now working for AIX builds\n  * deps/npm: upgrade npm to 3.10.10\n  * deps/V8: destructuring of arrow function arguments via computed\n             property no longer throws\n  * inspector: /json/version returns object, not an object wrapped\n               in an array\n  * module: using --debug-brk and --eval together now works\n            as expected\n  * process: improve performance of nextTick up to 20%\n  * repl: the division operator will no longer be accidentally\n          parsed as regex\n  * repl: improved support for generator functions\n  * timers: recanceling a cancelled timers will no longer throw\n\n- New upstream LTS version 6.9.2","id":"SUSE-SU-2017:0431-1","modified":"2017-02-09T10:18:00Z","published":"2017-02-09T10:18:00Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20170431-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1009528"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3731"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3732"}],"related":["CVE-2016-7055","CVE-2017-3731","CVE-2017-3732"],"summary":"Security update for nodejs6","upstream":["CVE-2016-7055","CVE-2017-3731","CVE-2017-3732"]}