<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: node.exe in Fusion Design, Validate &amp; Document Forum</title>
    <link>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791775#M287761</link>
    <description>&lt;P&gt;Secunia logs this as folows at&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://secunia.com/advisories/65282/" target="_blank"&gt;http://secunia.com/advisories/65282/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="small_p"&gt;A security issue has been reported in OpenSSL, which can be exploited by malicious people to bypass certain security restrictions.&lt;BR /&gt;&lt;BR /&gt;The security issue is caused due to an error when finding an alternative certificate chain, which can be exploited to bypass certain checks on untrusted certificates and accept an otherwise invalid certificate.&lt;BR /&gt;&lt;BR /&gt;The security issue is reported in versions 1.0.2c, 1.0.2b, 1.0.1n and 1.0.1o.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;BR /&gt;Update to version 1.0.2d or 1.0.1p.&lt;/P&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Provided and/or discovered by:&lt;/STRONG&gt;&lt;BR /&gt;The vendor credits Adam Langley and David Benjamin.&lt;/P&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Original Advisory:&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="http://www.openssl.org/news/secadv_20150709.txt" target="_blank"&gt;http://www.openssl.org/news/secadv_20150709.txt&lt;/A&gt;&lt;/P&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Deep Links:&lt;/STRONG&gt;&lt;BR /&gt;&lt;A title="Customers get access to additional unvetted links to a broad variety of 3rd party sources which provide information related to the advisory." href="http://secunia.com/vulnerability_intelligence/" target="_blank"&gt;Links available to Secunia VIM customers&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 27 Aug 2015 16:35:44 GMT</pubDate>
    <dc:creator>petermat</dc:creator>
    <dc:date>2015-08-27T16:35:44Z</dc:date>
    <item>
      <title>node.exe</title>
      <link>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5789397#M287759</link>
      <description>&lt;P&gt;Secunia PSI is telling me that the copies of node.exe installed by Fusion down in C:\Users\emad\AppData\Local\Autodesk\webdeploy\shared\Brackets\1.2.0c\WIN64\Brackets&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;C:\Users\emad\AppData\Local\Autodesk\webdeploy\production\dc51aa32319719d501b533ed310b20be48414459\Brackets&lt;/P&gt;&lt;P&gt;are out of date - which they are. They are 10.24 vs the current 12.7. Installing the current version does nothing to change this as the standard install goes to&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\nodejs&lt;/P&gt;&lt;P&gt;and installs a bunch more stuff than just node.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice on this situation?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 18:17:46 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5789397#M287759</guid>
      <dc:creator>petermat</dc:creator>
      <dc:date>2015-08-26T18:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: node.exe</title>
      <link>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791716#M287760</link>
      <description>&lt;P&gt;We use a lot of 3rd party components and don't necessarily update them without good cause. Is there a security advisory about this version of node that you are concerned about?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our next update this component will not be called until you access the functionality that uses it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let us know your concerns about this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 16:00:14 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791716#M287760</guid>
      <dc:creator>Phil.E</dc:creator>
      <dc:date>2015-08-27T16:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: node.exe</title>
      <link>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791775#M287761</link>
      <description>&lt;P&gt;Secunia logs this as folows at&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://secunia.com/advisories/65282/" target="_blank"&gt;http://secunia.com/advisories/65282/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="small_p"&gt;A security issue has been reported in OpenSSL, which can be exploited by malicious people to bypass certain security restrictions.&lt;BR /&gt;&lt;BR /&gt;The security issue is caused due to an error when finding an alternative certificate chain, which can be exploited to bypass certain checks on untrusted certificates and accept an otherwise invalid certificate.&lt;BR /&gt;&lt;BR /&gt;The security issue is reported in versions 1.0.2c, 1.0.2b, 1.0.1n and 1.0.1o.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;BR /&gt;Update to version 1.0.2d or 1.0.1p.&lt;/P&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Provided and/or discovered by:&lt;/STRONG&gt;&lt;BR /&gt;The vendor credits Adam Langley and David Benjamin.&lt;/P&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Original Advisory:&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="http://www.openssl.org/news/secadv_20150709.txt" target="_blank"&gt;http://www.openssl.org/news/secadv_20150709.txt&lt;/A&gt;&lt;/P&gt;&lt;P class="small_p"&gt;&lt;STRONG&gt;Deep Links:&lt;/STRONG&gt;&lt;BR /&gt;&lt;A title="Customers get access to additional unvetted links to a broad variety of 3rd party sources which provide information related to the advisory." href="http://secunia.com/vulnerability_intelligence/" target="_blank"&gt;Links available to Secunia VIM customers&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Aug 2015 16:35:44 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791775#M287761</guid>
      <dc:creator>petermat</dc:creator>
      <dc:date>2015-08-27T16:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: node.exe</title>
      <link>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791901#M287762</link>
      <description>&lt;P&gt;Hello Peter,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for bringing this issue to our attention. &amp;nbsp;I do not beleive that the version of node.exe delivered is used in such a way as to expose anyone to the vulnerability mentioned, but we have initiated the process for updating the component none-the-less.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the meantime, it is used primarily to support the Brackets IDE that is provided for the purpose of editing javascript add-ins in neutron. &amp;nbsp; As long as this functionality isn't used, the executable should not be launched. &amp;nbsp;If you are not a programmer, avoiding Brackets shoudln't be hard. &amp;nbsp;If you are a programmer, then you can use any editor of your preference instead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make your computer more secure in spite of the fact that you won't be using the exe, feel free to delete the node.exe files found in our installation folder... or if you prefer to replace them with the node.exe you downloaded... but since we have not tested with this version, we cannot guarantee that&amp;nbsp;this&amp;nbsp;will work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Steven&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 17:37:32 GMT</pubDate>
      <guid>https://forums.autodesk.com/t5/fusion-design-validate-document/node-exe/m-p/5791901#M287762</guid>
      <dc:creator>svelez</dc:creator>
      <dc:date>2015-08-27T17:37:32Z</dc:date>
    </item>
  </channel>
</rss>

