Notable Changes

These are vulnerabilities in the node-tar, arborist, and npm cli modules which
are related to the initial reports and subsequent remediation of node-tar
vulnerabilities CVE-2021-32803
and CVE-2021-32804.
Subsequent internal security review of node-tar and additional external bounty
reports have resulted in another 5 CVE being remediated in core npm CLI
dependencies including node-tar, and npm arborist.

You can read more about it in:

Commits

Windows 32-bit Installer: https://nodejs.org/dist/v12.22.6/node-v12.22.6-x86.msi
Windows 64-bit Installer: https://nodejs.org/dist/v12.22.6/node-v12.22.6-x64.msi
Windows 32-bit Binary: https://nodejs.org/dist/v12.22.6/win-x86/node.exe
Windows 64-bit Binary: https://nodejs.org/dist/v12.22.6/win-x64/node.exe
macOS 64-bit Installer: https://nodejs.org/dist/v12.22.6/node-v12.22.6.pkg
macOS Intel 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-darwin-x64.tar.gz
Linux 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-linux-x64.tar.xz
Linux PPC LE 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-linux-ppc64le.tar.xz
Linux s390x 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-linux-s390x.tar.xz
AIX 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-aix-ppc64.tar.gz
SmartOS 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-sunos-x64.tar.xz
ARMv7 32-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-linux-armv7l.tar.xz
ARMv8 64-bit Binary: https://nodejs.org/dist/v12.22.6/node-v12.22.6-linux-arm64.tar.xz
Source Code: https://nodejs.org/dist/v12.22.6/node-v12.22.6.tar.gz
Other release files: https://nodejs.org/dist/v12.22.6/
Documentation: https://nodejs.org/docs/v12.22.6/api/

SHASUMS


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

eb2fc7741587f5149178265cbc5b244d9a9cffb6a5fe62e20ee966d57ec9217a  node-v12.22.6-aix-ppc64.tar.gz
2124e9e17bf6b81ad579223f8efff537238c9cace17721e60614c5091f00e2d1  node-v12.22.6-darwin-x64.tar.gz
699eaa1550e79fdcd3d5f5080958a42b88f36cfe57760572a3a53e0d358f1ea6  node-v12.22.6-darwin-x64.tar.xz
85a6cb008dc40e97a3d1f8e3825d8b74210ecbee7d0d5177d1b80c942f3576a8  node-v12.22.6-headers.tar.gz
0782ad32a8e2d11e7da6d546ea068456effe1f228100f74ac98851b508692b0f  node-v12.22.6-headers.tar.xz
f65bf376b6b074b78240ea84d0ab7ca6cacb34c1c066b6653d76045a38565bc2  node-v12.22.6-linux-arm64.tar.gz
39b1ee686c78315c04593d2e216595d052ae3378d9e50a0a72d8f2dc95e69e58  node-v12.22.6-linux-arm64.tar.xz
90fdb1c46132c019d97c8cc40f0c02b01fa7dddfe733b030668c512112273b00  node-v12.22.6-linux-armv7l.tar.gz
a3495fb6361fdb05266b5a294448a24d0a97c8f1419422986083a32804109029  node-v12.22.6-linux-armv7l.tar.xz
46b1adefb66c525f519b5d0c918bd52650b061fa49ad2a1f7309dc7ba137ed35  node-v12.22.6-linux-ppc64le.tar.gz
e05ac6cf72cd28e201b96971858f6d6367bc08568056c92e918329b63c42f449  node-v12.22.6-linux-ppc64le.tar.xz
5d01cc9b1ac70d55c4cc24ab337675dfbf194241436f8a21cdc129b2643de5a5  node-v12.22.6-linux-s390x.tar.gz
5f9b580fc0d9cb412c0482ede23de2c68063942fecd44565cc0e509ed06b4d02  node-v12.22.6-linux-s390x.tar.xz
6e5ce9cc7dcd31b182730cd662b1813c201fa98089e1013db4abd141716852dc  node-v12.22.6-linux-x64.tar.gz
80fc80cdb3d829ea4d752c2e52067a426f6c4fd629ecca5a858d268af8d5ec7e  node-v12.22.6-linux-x64.tar.xz
cc854edac9b82a8b816c7f658c04fcd3a3748479fe0dcd2e5bc26dcd08ba4c24  node-v12.22.6.pkg
39727bd2853a3fc98e9f8fa97612e1901ce5c7c9070b5e14ed709b70e2fe3818  node-v12.22.6-sunos-x64.tar.gz
241fba8cb47dc0753e2baeab9c9d64b4c5bffa60b6e17697589b15c80e7a9bd3  node-v12.22.6-sunos-x64.tar.xz
02763dcf6532a997143b03c1f7d23552a3bd19ddcad1fd2425956db7596cbc9c  node-v12.22.6.tar.gz
c2022f16b8f689620c3472c2b5261fdabbd0ab976bf9ac3b7db6747a2e9b0f7a  node-v12.22.6.tar.xz
49ab4062f830a25eb2904281bbbda6a3fa2b7080bc2bdf73695b5c2b78597c89  node-v12.22.6-win-x64.7z
d35a21d6d7b517c6bf4132abfbbdd447dfe46f5e1de3194d5f4152395a1ac6a2  node-v12.22.6-win-x64.zip
e06b427d77274a650d6599fcffb09d3450fee8e4209dc6c8eb1d5b148b721500  node-v12.22.6-win-x86.7z
a62cdc9449973f2251b6a77365f36e00ab34d6ab2d179c8a8e4f0482282f8835  node-v12.22.6-win-x86.zip
a3f5a626a60ec9ad78cbd7162c6b847efd59fc36195a203316d47956c3081017  node-v12.22.6-x64.msi
4c1559f0eab12a27a8f344791b98cfa71eb86847722d2c27f85124dad89857f2  node-v12.22.6-x86.msi
b2edda82b5dd4a57c8e8971d0e15dcd5032166f6fc0624d48d5c08c4c42b4342  win-x64/node.exe
28e5c24831deedbf4fb8a9560f2c4f95205479c589f54a9a53ec346f6a5cf8bf  win-x64/node.lib
779755808bcbe3ba35c3e17d8e50574bac050b4cc6a03ed45707cc28f4905674  win-x64/node_pdb.7z
030414c7a5d69b4e76b4ab3d6fcfe148c644207f6f64dcfbcc9556967091dec4  win-x64/node_pdb.zip
4cff7813ce2eee6373c74be8c9663100e83eb1c59454b6de73d9b2ee07850c3e  win-x86/node.exe
dad0e6bef1c45f4f43fbf84c33df6b910ace8122eff3f8d39d5ebecd25320ba4  win-x86/node.lib
9ab6df86f89fdb58dc833c5fdafe2cf7472012e397501e8d69ad666e06e7ecb9  win-x86/node_pdb.7z
fffe9a7d636045cd3c836e5fafde830cc2a6fe01607e6d6686da67f7bf6311e3  win-x86/node_pdb.zip
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEDv/hvO/ZyE49CYFSkzsB9AtcqUYFAmEuQ80ACgkQkzsB9Atc
qUb1Ugf8CFIAKY0baA/DqoBMQ6TgROy39cXBuQPV+eczQA7tUrkabbwjoacgB0nV
xrtf5Q8jKZb0ooypyHmNBFlZQmhc/zvM4tDuKilSwiM1kRkZJ8zKYPGhxGz+2oUG
IeNhP2//lfOFS/Sc1YEi6xTGjehnRYQv/K5s8LV+TpuFJZzsXC2myxkEF68zeYa5
tqIEe6HSpmD6TMfKCXsXE6sUlmmdalm7roXoy+c6syBGsBMZZV972N/LZaROQOyM
r8z11IbUsJzoTr91OFCV+xHGbA9Z+0Dda0yzB2T9gF2NkierCzMEc/Auexi35HoP
bVw08kC1SyRLLGUBzqxQ9vFZawkYFA==
=zmbX
-----END PGP SIGNATURE-----
Categories: NewsReleases

0 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *