TPS-2016-001 Node.JS Vulnerability CVE-2015-8027 and CVE-2015-6764

SmartOS Users

New releases of the node.js packages have been added to the 2014Q4 pkgsrc repository. The following latest package releases address the vulnerabilities outlined in this notice:

  • nodejs-0.12.9.tgz
  • nodejs-4.2.3.tgz

If you are running on a SmartOS image that is using a different pkgsrc repository, you can still install the above by using the following command:

pkg_add http://pkgsrc.joyent.com/packages/SmartOS/2014Q4/x86_64/All/nodejs-0.12.9.tgz
pkg_add http://pkgsrc.joyent.com/packages/SmartOS/2014Q4/x86_64/All/nodejs-4.2.3.tgz

You can visit the Node.js website for more information about these vulnerabilities, and the specific releases that have been identified as vulnerable.

Please also refer to our most recent OpenSSL Security Advisory for details on the Node.js versions affected by the most recent OpenSSL CVE’s.

Linux Users

Please check the notices applicable to the Linux Distro you are using for the necessary remedial actions:


ORIGINAL NOTICE

This notice is to advise all Joyent Public Cloud (JPC) and SmartDataCenter (SDC) customers of the recently-identified Node.js security vulnerabilities CVE-2015-8027 and CVE-2015-6764. In the next coming days, Joyent will pro-actively update this notice confirming actions taken by Joyent, as well as provide specific details on any required actions that will need to be taken by both JPC and SDC customers.

For now, you can visit this Node.js website to obtain additional details. Again, we will update this notice with more information within the next several days, specific to actions that may be required by all JPC and SDC customers. Your attention to this matter is appreciated.

At any time, please do not hesitate to contact our Support team by raising a ticket at https://help.joyent.com or by email to support@joyent.com if you have any questions or concerns.