# New vulnerabilities in openssl

**URL:** <https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530>\
**Category:** SQLCipher\
**Created:** [July 3, 2024, 11:40pm UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530 "2024-07-03T23:40:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chen\_song](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/chen_song/32/1742_2.png) [@chen\_song](https://discuss.zetetic.net/u/chen_song)\
**Post date:** [July 3, 2024, 11:40pm UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530/1 "2024-07-03T23:40:10Z")

</div>

Hi  
Our scan tool reports vulnerabilities CVE-2023-3446,CVE-2024-2511,CVE-2024-4741,CVE-2024-5535 in openssl 1.1.1s used by sqlcipher  
Does these vulnerabilities affect net. zetetic:android-database-sqlcipher ?

Thanks

---

<div class="post-metadata">

**Author:** ![developernotes](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/developernotes/32/1309_2.png) [@developernotes](https://discuss.zetetic.net/u/developernotes)\
**Post date:** [July 5, 2024, 1:46pm UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530/2 "2024-07-05T13:46:07Z")

</div>

Hi @chen_song,

SQLCipher is not affected by CVE-2023-3446, CVE-2024-2511, or CVE-2024-5535 as it does not utilize Diffie–Hellman key exchange, nor TLS. I do not see any information currently available for CVE-2024-4741 \[1\] \[2\].

* * *

1. [NVD - CVE-2024-4741](https://nvd.nist.gov/vuln/detail/CVE-2024-4741) 

2. [CVE - CVE-2024-4741](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4741)

---

<div class="post-metadata">

**Author:** ![chen\_song](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/chen_song/32/1742_2.png) [@chen\_song](https://discuss.zetetic.net/u/chen_song)\
**Post date:** [July 6, 2024, 1:50am UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530/3 "2024-07-06T01:50:04Z")

</div>

Hi @developernotes, thank you for your reply.  
Detail about vunerability CVE-2024-4741 can be referenced from here:  
[https://www.openssl.org/news/vulnerabilities.html](https://www.openssl.org/news/vulnerabilities.html)

---

<div class="post-metadata">

**Author:** ![sjlombardo](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/sjlombardo/32/3_2.png) [@sjlombardo](https://discuss.zetetic.net/u/sjlombardo)\
**Post date:** [July 8, 2024, 1:52pm UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530/4 "2024-07-08T13:52:57Z")

</div>

@chen_song - SQLCipher is not affected by CVE-2024-4741 as it does not use `SSL_free_buffers`.

---

<div class="post-metadata">

**Author:** ![Cap\_KM](https://avatars.discourse-cdn.com/v4/letter/c/edb3f5/32.png) [@Cap\_KM](https://discuss.zetetic.net/u/Cap_KM)\
**Post date:** [October 8, 2025, 12:46pm UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530/5 "2025-10-08T12:46:07Z")

</div>

Hi @developernotes,

Thanks for the previous clarification regarding CVE-2023-3446, CVE-2024-2511, CVE-2024-4741, and CVE-2024-5535 not affecting net.zetetic:android-database-sqlcipher due to the absence of TLS, Diffie–Hellman, and `SSL_free_buffers`.

Could you please confirm if this is still the case for **`net.zetetic:sqlcipher-android`** (e.g. 4.6.1 or newer)?  
We’d just like to confirm that no recent updates have introduced any new dependencies or usage of OpenSSL components that could potentially be affected by these CVEs.

Thanks a lot for your work !

---

<div class="post-metadata">

**Author:** ![developernotes](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/developernotes/32/1309_2.png) [@developernotes](https://discuss.zetetic.net/u/developernotes)\
**Post date:** [October 9, 2025, 1:25pm UTC](https://discuss.zetetic.net/t/new-vulnerabilities-in-openssl/6530/6 "2025-10-09T13:25:01Z")

</div>

Hi @Cap_KM,

> [@Cap\_KM](#):
>
> Thanks for the previous clarification regarding CVE-2023-3446, CVE-2024-2511, CVE-2024-4741, and CVE-2024-5535 not affecting net.zetetic:android-database-sqlcipher due to the absence of TLS, Diffie–Hellman, and `SSL_free_buffers`.
> 
> Could you please confirm if this is still the case for **`net.zetetic:sqlcipher-android`** (e.g. 4.6.1 or newer)?

Those CVE’s do not apply to `sqlcipher-android` either.
