bees4honey / mobile_vin_scanner

This is a repo for Mobile VIN Scanner created by bees4honey.
Other
73 stars 42 forks source link

libb4hvinscanner.so statically links to a version of OpenSSL with multiple vulnerabilities #8

Closed gautamc closed 8 years ago

gautamc commented 9 years ago

https://www.openssl.org/news/vulnerabilities.html - OpenSSL 1.0.1l has known vulnerabilities. Due to this Google Play Store is displaying a warning for apps that are using this library. Would be great if these libraries were rebuilt to statically link with the version of OpenSSL containing fixes.

$ wget https://github.com/bees4honey/mobile_vin_scanner/blob/master/android_scanner_sdk/libs/armeabi-v7a/libb4hvinscanner.so?raw=true -O libb4hvinscanner.so

$ sum libb4hvinscanner.so 17 994 libb4hvinscanner.so

$ strings libb4hvinscanner.so |grep "OpenSSL 1.0.1l" lhash part of OpenSSL 1.0.1l 15 Jan 2015 PEM part of OpenSSL 1.0.1l 15 Jan 2015 RSA part of OpenSSL 1.0.1l 15 Jan 2015 SHA1 part of OpenSSL 1.0.1l 15 Jan 2015 Stack part of OpenSSL 1.0.1l 15 Jan 2015 X.509 part of OpenSSL 1.0.1l 15 Jan 2015 ASN.1 part of OpenSSL 1.0.1l 15 Jan 2015 Big Number part of OpenSSL 1.0.1l 15 Jan 2015 Diffie-Hellman part of OpenSSL 1.0.1l 15 Jan 2015 DSA part of OpenSSL 1.0.1l 15 Jan 2015 (1EC part of OpenSSL 1.0.1l 15 Jan 2015 ECDSA part of OpenSSL 1.0.1l 15 Jan 2015 EVP part of OpenSSL 1.0.1l 15 Jan 2015 MD5 part of OpenSSL 1.0.1l 15 Jan 2015 RAND part of OpenSSL 1.0.1l 15 Jan 2015 SHA-256 part of OpenSSL 1.0.1l 15 Jan 2015 SHA-512 part of OpenSSL 1.0.1l 15 Jan 2015 CONF part of OpenSSL 1.0.1l 15 Jan 2015 ECDH part of OpenSSL 1.0.1l 15 Jan 2015 ECONF_def part of OpenSSL 1.0.1l 15 Jan 2015