Cve-2022-1292 cve-2022-2068 cve-2021-3711 cve-2022-0778 cve-2021-3450 cve-2021-3712 cve-2021-4160 cve-2021-3449 cve-2022-2097

Our internal binary scan tool reported below vulnerabilities

CVE-2022-1292
CVE-2022-2068
CVE-2021-3711
CVE-2022-0778
CVE-2021-3450
CVE-2021-3712
CVE-2021-4160
CVE-2021-3449
CVE-2022-2097

Do these vulnerabilities affect the zetetic library “net.zetetic:android-database-sqlcipher:4.4.3” ?
If yes, could you explain the rationale?
What is the fix plan?

Hello @shiva . You should consider upgrading to SQLCipher 4.5.2.

Currently we are using 4.4.3version and Kindly let us know whether the above vulnerabilities affect this library (“net.zetetic:android-database-sqlcipher:4.4.3”)

If you google sqlcipher followed by the CVE string you will find our comments on every one of those CVEs from previous posts. If you are an existing commercial or enterprise edition subscriber you can contact us at support@zetetic.net for summarized feedback.