Vulnerability
APK Version(s)
Libpng libraryThe vulnerabilities were fixed in libpng v1.0.66, v.1.2.56, v.1.4.19, v1.5.26 or higher. You can find more information about how resolve the issue in this Google Help Center article.
OpenSSLThe vulnerabilities were addressed in OpenSSL 1.0.2f/1.0.1r. To confirm your OpenSSL version, you can do a grep search for:
$ unzip -p YourApp.apk | strings | grep "OpenSSL"
You can find more information and next steps in this Google Help Center article.
- libpng漏洞, 更新最新的libpng:
cocos2dx目錄為: /Applications/android/cocos2dx/cocos2dx2.2.6_fixlibpng/cocos2dx/platform/third_party/android/prebuilt/libpng
解決文章:
https://stackoverflow.com/questions/37852634/cocos2dx-libpng-google-play-notification-june-2016
http://blog.csdn.net/qingzijin2010/article/details/52037723
下載鏈接:
https://sourceforge.net/projects/libpng/files/
https://pan.baidu.com/s/1slhAznv
檢查:
unzip -p pro.android.xx.apk | strings | grep "libpng"
直接檢查libcocos2dcpp.so文件
strings libcocos2dcpp.so | grep libpng
2.OpenSSL 漏洞
cocos2dx的 curl存在漏洞, 修復(fù)方法是找到修補(bǔ)后的版本, 然后替換
解決文章:
http://blog.cocos2d-x.org/2016/04/openssl-update/
http://forum.cocos.com/t/cocos2dx-3-x-curl-openssl/37338
http://www.bengigi.com/cocos2d-x-fix-for-openssl-problem/
http://blog.csdn.net/zhongjuelong/article/details/70242788
http://www.bubuko.com/infodetail-1063060.html
下載鏈接:
OpenSSL 1.0.1h
http://download.csdn.net/detail/lwuit/8675511
檢查:
unzip -p YourApp.apk | strings | grep "OpenSSL"
直接檢查libcocos2dcpp.so文件
strings libcocos2dcpp.so | grep "OpenSSL"
3.確保cocos2dx環(huán)境變量對(duì)應(yīng)正確
mac下的cocos2dx環(huán)境變量并不會(huì)根據(jù)eclipse引用cocos2dx java項(xiàng)目而更改, 害的我改了半天也沒(méi)用
4.確保cocos2dx資源對(duì)應(yīng)正確
手頭上有好幾版cocos2dx版本, 這導(dǎo)致了內(nèi)容混淆, 而且我之前的項(xiàng)目是通過(guò)cocos2dx 2.2.5生成的, 然后改系統(tǒng)變量和android.mk配置都無(wú)效, 最后eclipse內(nèi)部搜索工程設(shè)置里的path, 找到對(duì)應(yīng)的c++編譯路徑, 修改掉.
5.最后的最后別忘了刪掉libs和obj下的文件, 否則會(huì)產(chǎn)生緩存沖突
6.不用必須release出apk來(lái)監(jiān)測(cè)版本, 直接對(duì)libcocos2dcpp.so就可以查詢
最后截取兩個(gè)版本的檢測(cè)信息
libpng:
OpenSSL:(比較長(zhǎng), 只截了部分的, 只要找到版本是更新的就對(duì)了)