[Interest] Google Play 60-day deadline for resolving OpenSSL vulnerabilities

Nuno Santos nunosantos at imaginando.pt
Thu May 7 22:54:54 CEST 2015


Hi,

I have just received this message from Google Play.

Since I haven’t linked with OpenSSL explicitly, is there any chance of this being an implicit link from Qt.

My app only links with Parse (1.3.0) regarding external libraries.

Does anyone else has received this message?

Thanks,

Regards,

Nuno

> On 07/05/2015, at 21:49, Google Play Developer Support <noreply-developer-googleplay at google.com> wrote:
> 
> We wanted to let you know that your app(s) listed below statically link against a version of OpenSSL that has multiple security vulnerabilities for users. Please migrate your app(s) to an updated version of OpenSSL within 60 days of this notification. Beginning 7/7/15, Google Play will block publishing of any new apps and updates that use older, unsupported versions of OpenSSL (see below for details).
> 
> REASON FOR WARNING: Violation of the dangerous products <https://www.google.com/appserve/mkt/p/OoKK-5HOnMydgLCrcb4gARSZViNwyV2mNBilh4ixv4FoBO4e0nnDuktXPrIEICn57zodLXg4v7R2TjefPeKVZ_5_p8Db_K4RMQnEZ0ffyNma2xGpWA==> provision of the Content Policy and section 4.4 <https://www.google.com/appserve/mkt/p/04U0c1o5WBlN0oUM8ZnT418RIfSmwWE5_dYqjjUlYQyHBr0cyz-lXNiuIGDdBSqcSvFRnOtTLavaoYcXxjtwkCGMXLxjqRMsoJ-lefS_GjEjTbhGv0FuSg_6ysGpYA==> of the Developer Distribution Agreement.
> 
> The vulnerabilities were fixed in OpenSSL versions beginning with 1.0.1h, 1.0.0m, and 0.9.8za. To confirm your OpenSSL version, you can do a grep via: $ unzip -p YourApp.apk | strings | grep "OpenSSL"
> 
> For more information about the vulnerability, please see this OpenSSL Security Advisory <http://www.google.com/appserve/mkt/p/X-XkB-ETwE8q7_j8QkTYjlv_MXQ2wiowvehOiMMu6vj7o1onXtJW8avOIVv-fEJaTjATvnx1MlF5TCb-NqQr>. To confirm that you’ve upgraded correctly, upload the updated version of the app(s) to the Developer Console and check back after five hours. For other technical questions about managing OpenSSL, please see https://groups.google.com/forum/#!forum/mailing.openssl.users <https://www.google.com/appserve/mkt/p/RVmUlFzQje5g1yg_aZD35OYwJRBSge1BIN-3OHM0tIfh8vw4UlbxjF0qG1xfqs_Oyz3vgjA6Z05ws1VdwgoNWBksgs1n4C4XCJEZ7Xw=>.
> 
> In 60 days, we will not accept app updates containing the vulnerabilities. In addition, we will reject new apps containing the vulnerabilities.
> 
> Note: while the issues may not affect every app that uses OpenSSL versions prior to 1.0.1h, 1.0.0m, or 0.9.8za, developers should stay up to date on all security patches. Even if you think that specific issues may not be relevant, it's good practice to update any libraries in your app that have known issues. Please take this time to update apps that have out-of-date dependent libraries or other vulnerabilities.
> 
> Before publishing applications, please ensure your apps’ compliance with the Developer Distribution Agreement <https://www.google.com/appserve/mkt/p/i7foJyvDgXYPnX9tuHOPTShbsTclfBP8y9vd1S3kOl_7NXg5vraDGJ_WbKaLxioeZKZFcRCGYJ3lubgPbNgGcGrTZ5r1jjHwiDnYtj1_Eg-it0w=> and Content Policy <https://www.google.com/appserve/mkt/p/53E7nnIX_G36FwSp5vVIHp6ZQ_6MJe5xjIMt6e00tAp20MlWNrXsFHelGaAIuLY_rQkC8e9fWd3F6a3igLoejdNCt2brV5Idvfeg>. If you feel we have sent this warning in error, visit this Google Play Help Center article <http://www.google.com/appserve/mkt/p/hTMrpgpnOZ5qeTIetcdLGROEsDZ1drwg1-7QY-_KGcrYg6f4n7tZ_mEloSTDc-0R8u2kZW1tc8hLULbZHx6ES_1eOSSVkQoIBimFjPXh7Qyooc1->.
> 
> Regards,
> Google Play Team
> 
> Affected application(s):
> 
> LK - Ableton Live Controller: com.imaginando.lk
> ©2015 Google Inc. 1600 Amphitheatre Parkway, Mountain View, CA 94043
> 
> Email preferences: You have received this mandatory email service announcement to update you about important changes to your Google Play Developer account.
> 
> 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.qt-project.org/pipermail/interest/attachments/20150507/d10b68e3/attachment.html>


More information about the Interest mailing list