Announcements
The Scaleform forum is now read-only. Please head to the Gamedev site for product support.
Scaleform Forum (Read Only)
Scaleform enables developers to leverage the power of the Adobe® Flash® tool set to create powerful user interface environments for video games.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Android security alert about libpng

9 REPLIES 9
SOLVED
Reply
Message 1 of 10
Azicuetano
2666 Views, 9 Replies

Android security alert about libpng

Dear support team,

 

Today I recibed from Google this security alert about libpng:

 

Security Alert
Your application uses a version of libpng that contains a security vulnerability. Access to this article Google Help Center for more information on, for example, the deadline to resolve the vulnerability.
It affects version 11 of the APK".

 

https://support.google.com/faqs/answer/7011127

 

Scaleform libpng versión is 1.5.13, and is affected by this security issue.

 

It would be possible get Scaleform Android Mobile with a new versión of libpng, please?

Too many thanks in advance!!

- Developer at Grupo Enfoca -
Tags (1)
9 REPLIES 9
Message 2 of 10
SFjenkink
in reply to: Azicuetano

Hi we are currently looking into this, i can provide you with a link to our updated libpng libs once they are ready. 

 

-Kevin 

Message 3 of 10
SFjenkink
in reply to: SFjenkink

hi please use the zip here for the updated libpng https://autodesk.box.com/s/z2srbnnu8q2x5wwjlrcld3qnlu83uvd3 

 

you can copy that to the 3rd party directory in the distribution , from there in that zip there is a lib directory that contains a 3rdParty.mk which you need to copy to Projects/Common if you wish to rebuild the lib at a later date. 

 

Also from that lib directory please copy the libpng.a to the Libs/Android/arm for use with your app. 

 

let me know if there are any issues. 

 

-SFjenkink

Message 4 of 10
Azicuetano
in reply to: SFjenkink

Thanks SFjenkink!! 😄

I get an error in your link (if anyone click the link get a 404), but I found the correct link: https://autodesk.app.box.com/s/z2srbnnu8q2x5wwjlrcld3qnlu83uvd3

 

In 3 or 4 days I will test this patch and I'll post here if it has worked fine.

I hope I can follow your instructions 🙂

 

To many thanks again SFjenkink!!!!

 

- Developer at Grupo Enfoca -
Message 5 of 10
Azicuetano
in reply to: SFjenkink

Hi SFJenkink!

 

All works fine!! I've followed your instructions and I've used the Deployer to create the APK. The compiling process was successfull, with no errors.

I've just uploaded the APK to Google Play Store and the app is now published. Until now, I have no warning messages 🙂

 

To many thanks again SFJenkink!!!!!!!!!

- Developer at Grupo Enfoca -
Message 6 of 10
unity007
in reply to: Azicuetano

Does this solution also work for Scaleform for Unity3D or only for Scaleform for Android?

 

With Scaleform for Unity3d we receive the same error from the Google Play store ; the app built with Scaleform for Unity3D has been removed from the Playstore because of the vulnerable libpng library compiled into the libgfxunity3d.so file.

 

Is there a way to solve this without waiting for an update of the Unity3D plugin of Scaleform?

 

 

Message 7 of 10
Azicuetano
in reply to: SFjenkink

About 6 months ago SFienkink help us with a new version of libpng for Scaleform to avoid a security issue in Google Play.

This fix updates libpng to 1.5.27 version, but a new security issue with this version are published recently, and Google Play don't let us update our app or publish a new one created with Sacaleform Mobile for Android.

Here is release of this security problem on the libpng project website: http://www.libpng.org/pub/png/libpng.html
And here's some news: http://www.securityweek.com/libpng-patches-flaw-introduced-1995
In the official statement detail how version 1.5.28 (and 1.6.28,...) are free of this problem of security ...

Please, Kevin, could you provide a patch with a Google-friendly version of Libpng? I am really desperate and very pressured by a client because I can not find the way to publish the new version... May be @MatthewDoyleArt could take a llok to this problem? 🙂

Thank you very much in advance!!!

- Developer at Grupo Enfoca -
Tags (2)
Message 8 of 10
SFjenkink
in reply to: Azicuetano

Hi @Azicuetano ive made an updated zip for 1.5.28 please download it from here https://autodesk.box.com/s/l4qhbddwmcy60p2lvyp0mi67fpw9g491

 

You can use the same instructions as detailed in my earlier post. Please let me know if you encounter any issues. 

 

-SFJenkink

Message 9 of 10
Azicuetano
in reply to: SFjenkink

Hi SFJenkink!!

All works perfect! 😉

 

I have build my project with your last update for pnglib 1.5.28 with no problems. I've upload the APK to Google Play for beta test and... all works fine without security alerts!!

^_^ I'm really happy!!!!!

 

To many thanks Kevin. It is a pleasure to have your support. I am deeply grateful to you. Thanks!!!!

- Developer at Grupo Enfoca -
Message 10 of 10
cyrusmiley847
in reply to: Azicuetano

Android devices should be made very much secure as majority of the population uses android and if their data is not in safe hands then what's the need of developing such a device!!! Xmodgames app

Can't find what you're looking for? Ask the community or share your knowledge.

Post to forums  

Autodesk Design & Make Report