<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google Play security warning in ArcGIS AppStudio Questions</title>
    <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853545#M2848</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this notification too. How did you detect that esri library use libpng library ? Google play developer console only says that your app affected due to the previous version of libpng. I ask this question because I use many libraries in my project. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Jun 2016 06:04:05 GMT</pubDate>
    <dc:creator>SalihYalcin</dc:creator>
    <dc:date>2016-06-17T06:04:05Z</dc:date>
    <item>
      <title>Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853541#M2844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I received the following message today from Google Play.&amp;nbsp; I assume that the file to which they refer is part of the template.&amp;nbsp; I know you are making updates, so perhaps this is already included.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello Google Play Developer,&lt;/P&gt;&lt;P&gt;We detected that your app(s) listed at the end of this email are using an unsafe version of the &lt;A href="http://www.google.com/appserve/mkt/p/90zdrGq7t9QihePF2hwhv5bm9VgzemZgCvE6tDIjeIW0yL0R1jJnBZokxWA_c_YtNjVKPqjyY5ge"&gt;libpng&lt;/A&gt; library. Apps with vulnerabilities like this can expose users to risk of compromise and may be considered in violation of our &lt;A href="https://www.google.com/appserve/mkt/p/ONdfaDBbu4beqV9htDbD6uRZnQR1U1e5r1v--mQDvag4SmSj82KPx-m82B-hHqbBlMJaJWB0kwSBAQk0IBvk-dgkznMpHn1RhdsUdq8S0qERqF0="&gt;Malicious Behavior&lt;/A&gt; policy.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What’s happening&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Beginning September 17, 2016, Google Play will block publishing of any new apps or updates that use vulnerable versions of libpng. Your published APK version will not be affected, however any updates to the app will be blocked unless you address this vulnerability.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Action required&lt;/STRONG&gt;: Migrate your app(s) to use libpng v1.0.66, v.1.2.56, v.1.4.19, v1.5.26 or higher as soon as possible and increment the version number of the upgraded APK.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Next steps&lt;/STRONG&gt;&lt;BR /&gt; &lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Download the latest version of libpng from the &lt;A href="http://www.google.com/appserve/mkt/p/90zdrGq7t9QihePF2hwhv5bm9VgzemZgCvE6tDIjeIW0yL0R1jJnBZokxWA_c_YtNjVKPqjyY5ge"&gt;libpng website&lt;/A&gt;. &lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.google.com/appserve/mkt/p/C_iegGyLwRD5PZ0iBDrxiiWbyUgDHniNY9uxYDdxRwXPdn0Vd5jFvYfOALax8qaDFCpkaCQ="&gt;Sign in to your Developer Console&lt;/A&gt; and submit the updated version of your app. &lt;/LI&gt;&lt;LI&gt;Check back after five hours - we’ll show a warning message if the app hasn’t been updated correctly. &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The vulnerability stems from an out of bounds memory access that could potentially lead to code execution. Versions 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 are affected.&lt;/P&gt;&lt;P&gt;You can read more about the vulnerability in &lt;A href="https://www.google.com/appserve/mkt/p/5oHq9Dw4Zs8Eih6dbSCTVuiBcdiv26fCPNWspncuoYzaXc3r6Mf2lPapq9c44n1vT2yt80BboFbn5UMcHIG-W63iqmJw4_Vn2zav2yM="&gt;CVE-2015-8540&lt;/A&gt;. For other technical questions about the vulnerability, you can post to &lt;A href="https://www.google.com/appserve/mkt/p/KKLPTieUezto5ts03xMtKBnrkx70S8i37kk7P3NKzvXH-Bdw1KVRKnwF-MH39nZysLq2QPiHSP8="&gt;Stack Overflow&lt;/A&gt; and use the tag “android-security.”&lt;/P&gt;&lt;P&gt;While these specific issues may not affect every app that uses libpng, it’s best to stay up to date on all security patches.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We’re here to help&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you feel we have sent this warning in error, you can contact our &lt;A href="https://www.google.com/appserve/mkt/p/GGon65rqdsUnXc3ZdOxdMVAs0XJ0rZt6hSnaT52vmHselZdGTnfQ-_6Yjna-7ZIfyNl0NSuvCLRPONFeN1NziLM2B8HBnvOQKxx3jz9WupIGYFyCEtBK9cEo-g=="&gt;developer support team&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;The Google Play Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Affected app(s) and version(s) are listed below. If you have more than 20 affected apps in your account, please check the Developer Console for a full list.&lt;/P&gt;&lt;P&gt;com.esri.appdede77e19d354ae09a093d94937a760e&amp;nbsp;&amp;nbsp; 1000006&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 17:45:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853541#M2844</guid>
      <dc:creator>BrianHovis</dc:creator>
      <dc:date>2016-06-16T17:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853542#M2845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When will this be addressed? This is a showstopper issue for us. Please advise. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 18:29:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853542#M2845</guid>
      <dc:creator>JasonKiesel</dc:creator>
      <dc:date>2016-06-16T18:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853543#M2846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I am sure ESRI advisers will let us know.&amp;nbsp; I am just reporting what happened to me as a user.&amp;nbsp; &lt;A href="https://community.esri.com/migrated-users/37732"&gt;Sathya Prasad&lt;/A&gt;​&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 19:17:50 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853543#M2846</guid>
      <dc:creator>BrianHovis</dc:creator>
      <dc:date>2016-06-16T19:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853544#M2847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AppStudio team and the ArcGIS Runtime team are looking into this issue. We will update soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to clarify:&lt;/P&gt;&lt;P&gt;Only new apps and update to existing apps submitted on Google Play (after Sept 2016) will be affected by this announcement. Current apps will continue to be available and users can search and download. They have given us sufficient time to handle the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 22:36:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853544#M2847</guid>
      <dc:creator>SathyaPrasad</dc:creator>
      <dc:date>2016-06-16T22:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853545#M2848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this notification too. How did you detect that esri library use libpng library ? Google play developer console only says that your app affected due to the previous version of libpng. I ask this question because I use many libraries in my project. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2016 06:04:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853545#M2848</guid>
      <dc:creator>SalihYalcin</dc:creator>
      <dc:date>2016-06-17T06:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853546#M2849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I use the AppStudio template and only have one app.&amp;nbsp; I guessed that the libpng warning was related to the template, and therefore out of my control.&amp;nbsp; I was glad to see that the AppStudio and ArcGis Runtime teams are on top of this and will have it all handled by September.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2016 17:58:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853546#M2849</guid>
      <dc:creator>BrianHovis</dc:creator>
      <dc:date>2016-06-17T17:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853547#M2850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i am also having the same issue&lt;BR /&gt;Hopefully it gets fixed soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2016 21:17:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853547#M2850</guid>
      <dc:creator>AkhilSharma</dc:creator>
      <dc:date>2016-06-20T21:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853548#M2851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I used the following command in Terminal on my Mac&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;unzip -p arcgis-android-v10.2.8.aar | strings | grep "libpng"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;This will show you the version of libpng used in the aar/jar/apk file&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2016 21:19:19 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853548#M2851</guid>
      <dc:creator>AkhilSharma</dc:creator>
      <dc:date>2016-06-20T21:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853549#M2852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI- An official defect with Support has been logged for this issue # &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;BUG-000097435 : Vulnerability with libpng for Google Play Android .&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 15:49:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853549#M2852</guid>
      <dc:creator>nakulmanocha</dc:creator>
      <dc:date>2016-06-27T15:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853550#M2853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.esri.com/migrated-users/15508"&gt;Nakul Manocha&lt;/A&gt; Where can I find this Bugreport?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jul 2016 15:42:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853550#M2853</guid>
      <dc:creator>DominicBestler</dc:creator>
      <dc:date>2016-07-21T15:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853551#M2854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI this issue has been fixed in version &lt;SPAN class="pl-s" style="color: #183691;"&gt;10.2.8-1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="pl-s" style="color: #183691;"&gt;&lt;A href="https://github.com/Esri/arcgis-runtime-samples-android/issues/172" title="https://github.com/Esri/arcgis-runtime-samples-android/issues/172"&gt;Google Play security warning due to the libpng library version · Issue #172 · Esri/arcgis-runtime-samples-android · GitH…&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jul 2016 16:06:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853551#M2854</guid>
      <dc:creator>AkhilSharma</dc:creator>
      <dc:date>2016-07-25T16:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853552#M2855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is supposed to show up on the &lt;A href="http://support.esri.com/" title="http://support.esri.com/"&gt;Esri Support Home&lt;/A&gt; page. Unfortunately, it is not public yet. But rest assured the team is working on it to get it fixed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2016 00:13:03 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853552#M2855</guid>
      <dc:creator>nakulmanocha</dc:creator>
      <dc:date>2016-07-28T00:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Google Play security warning</title>
      <link>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853553#M2856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The runtime fix has now been applied to the AppStudio cloud &lt;STRONG&gt;Make&lt;/STRONG&gt; service. You do not need to install a new version of AppStudio to make use of this fix - just build your app again with cloud &lt;STRONG&gt;Make&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2016 04:00:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-appstudio-questions/google-play-security-warning/m-p/853553#M2856</guid>
      <dc:creator>MarikaVertzonis</dc:creator>
      <dc:date>2016-08-17T04:00:40Z</dc:date>
    </item>
  </channel>
</rss>

