# Cve-2021-3711, cve-2021-3712, cve-2021-3450 & cve-2021-3449

**URL:** <https://discuss.zetetic.net/t/cve-2021-3711-cve-2021-3712-cve-2021-3450-cve-2021-3449/5141>\
**Category:** SQLCipher\
**Created:** [October 11, 2021, 2:39pm UTC](https://discuss.zetetic.net/t/cve-2021-3711-cve-2021-3712-cve-2021-3450-cve-2021-3449/5141 "2021-10-11T14:39:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![surajitk](https://avatars.discourse-cdn.com/v4/letter/s/5f9b8f/32.png) [@surajitk](https://discuss.zetetic.net/u/surajitk)\
**Post date:** [October 11, 2021, 2:39pm UTC](https://discuss.zetetic.net/t/cve-2021-3711-cve-2021-3712-cve-2021-3450-cve-2021-3449/5141/1 "2021-10-11T14:39:08Z")

</div>

Hi Team，

The following critical and high severity vulnerabilities have been discovered in **OpenSSL 1.1.1j** recently.

- CVE-2021-3711
- CVE-2021-3712
- CVE-2021-3450
- CVE-2021-3449

Do these vulnerabilities affect the zetetic libraries like **zetetic-sqlcipher-windows** & **zetetic-sqlcipher-windows-uap**?  
Are these vulnerabilities false positive? If yes, could you explain the rationale?  
Also, Is there a plan for a new release with the fix?

Thanks.

---

<div class="post-metadata">

**Author:** ![sjlombardo](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/sjlombardo/32/3_2.png) [@sjlombardo](https://discuss.zetetic.net/u/sjlombardo)\
**Post date:** [October 11, 2021, 4:14pm UTC](https://discuss.zetetic.net/t/cve-2021-3711-cve-2021-3712-cve-2021-3450-cve-2021-3449/5141/2 "2021-10-11T16:14:18Z")

</div>

Hello @surajitk - SQLCipher is not affected by these vulnerabilities because it does not utilize SM2, public key cryptographic operations, TLS, or X.509. Thus SQLCipher 4.4.3 packages like zetetic-sqlcipher-windows and zetetic-sqlcipher-windows-uap are not impacted.

We are planning a new SQLCipher release in the near future. The updated It will include an updated version of OpenSSL

---

<div class="post-metadata">

**Author:** ![sjlombardo](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/sjlombardo/32/3_2.png) [@sjlombardo](https://discuss.zetetic.net/u/sjlombardo)\
**Post date:** [November 1, 2021, 4:37pm UTC](https://discuss.zetetic.net/t/cve-2021-3711-cve-2021-3712-cve-2021-3450-cve-2021-3449/5141/3 "2021-11-01T16:37:23Z")

</div>

The latest OpenSSL version 1.1.1l is used in SQLCipher 4.5.0.
