Hi Ralph, 

I logged a call back in December regarding this, it is logged under bug 14257 
which has been confirmed.

I have today chased for an update as we are also getting this notification. 

Paul 

-----Original Message-----
From: use-livecode [mailto:use-livecode-boun...@lists.runrev.com] On Behalf Of 
Ralph DiMola
Sent: 07 May 2015 21:59
To: 'How to use LiveCode'
Subject: Google Play Store and openSSL

Just got this from Google..... Does anyone know what version of OpenSSL LC uses?


We wanted to let you know that your app(s) listed below statically link against 
a version of OpenSSL that has multiple security vulnerabilities for users. 
Please migrate your app(s) to an updated version of OpenSSL within 60 days of 
this notification. Beginning 7/7/15, Google Play will block publishing of any 
new apps and updates that use older, unsupported versions of OpenSSL (see below 
for details).

REASON FOR WARNING: Violation of the dangerous products provision of the 
Content Policy and section 4.4 of the Developer Distribution Agreement.
The vulnerabilities were fixed in OpenSSL versions beginning with 1.0.1h, 
1.0.0m, and 0.9.8za. To confirm your OpenSSL version, you can do a grep via: $ 
unzip -p YourApp.apk | strings | grep "OpenSSL"

For more information about the vulnerability, please see this OpenSSL Security 
Advisory. To confirm that you’ve upgraded correctly, upload the updated version 
of the app(s) to the Developer Console and check back after five hours. For 
other technical questions about managing OpenSSL, please see 
https://groups.google.com/forum/#!forum/mailing.openssl.users. 

In 60 days, we will not accept app updates containing the vulnerabilities. In 
addition, we will reject new apps containing the vulnerabilities.
Note: while the issues may not affect every app that uses OpenSSL versions 
prior to 1.0.1h, 1.0.0m, or 0.9.8za, developers should stay up to date on all 
security patches. Even if you think that specific issues may not be relevant, 
it's good practice to update any libraries in your app that have known issues. 
Please take this time to update apps that have out-of-date dependent libraries 
or other vulnerabilities.

Before publishing applications, please ensure your apps’ compliance with the 
Developer Distribution Agreement and Content Policy. If you feel we have sent 
this warning in error, visit this Google Play Help Center article.
Regards,
Google Play Team

Ralph DiMola
IT Director
Evergreen Information Services
rdim...@evergreeninfo.net


_______________________________________________
use-livecode mailing list
use-livecode@lists.runrev.com
Please visit this url to subscribe, unsubscribe and manage your subscription 
preferences:
http://lists.runrev.com/mailman/listinfo/use-livecode
_______________________________________________
use-livecode mailing list
use-livecode@lists.runrev.com
Please visit this url to subscribe, unsubscribe and manage your subscription 
preferences:
http://lists.runrev.com/mailman/listinfo/use-livecode

Reply via email to