Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Important: Critical security issue fixed in 5.1.3. All users should upgrade. #87

Closed
feross opened this issue Jan 2, 2016 · 2 comments
Closed
Labels

Comments

@feross
Copy link
Member

feross commented Jan 2, 2016

We just fixed a security issue in the bittorrent-dht module that would allow an attacker to send a specific series of messages to a listening peer to make it disclose internal memory of the node.js process.

All users of bittorrent-dht should upgrade to version 5.1.3 or later.

@feross feross changed the title IMPORTANT: Critical security issue fixed in 5.1.3. All users should upgrade. Important: Critical security issue fixed in 5.1.3. All users should upgrade. Jan 2, 2016
@feross
Copy link
Member Author

feross commented Jan 2, 2016

Relevant issue on node.js tracker: nodejs/node#4514

@feross
Copy link
Member Author

feross commented Jan 2, 2016

All versions of bittorrent-dht less than 5.1.3 have been deprecated on npm, so users installing those versions should get a warning to upgrade to a newer version.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant