We have just had the following email from Google Play:
Security Alert: You are using a highly vulnerable version of OpenSSL
Hello,
One or more of your apps is running an outdated version of OpenSSL, which has multiple security vulnerabilities. You should update OpenSSL as soon as possible. For more information about the most recent security vulnerability in OpenSSL, please see http://www.openssl.org/news/secadv_20140605.txt.
Please note, while it’s unclear whether these specific issues affect your application, applications with vulnerabilities that expose users to risk of compromise may be considered “dangerous products” and subject to removal from Google Play.
_Regards,
Google Play Team_
The url has some info including the following:
OpenSSL 1.0.1 SSL/TLS users (client and/or server) should upgrade to 1.0.1h.
We built our apks after the plugin was last updated, and we’ve noticed that the OpenSSL plugin currently available to us is using 1.0.1g.
Can someone from Corona please let us know what the situation is ASAP?