4.3

CVE-2011-4447

The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitcoin ≫ Bitcoin Core Version 0.4.0
Bitcoin ≫ Bitcoin Core Version 0.4.1 Update rc6
Bitcoin ≫ Bitcoin Core Version 0.5.0 Update rc
Bitcoin ≫ Wxbitcoin Version 0.4.0
Bitcoin ≫ Wxbitcoin Version 0.4.1 Update rc6
Bitcoin ≫ Wxbitcoin Version 0.5.0 Update rc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.63% 0.731
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://en.bitcoin.it/wiki/CVEs
Vendor Advisory
http://bitcoin.org/releases/2011/11/21/v0.5.0.html
https://bitcointalk.org/index.php?topic=51474.0
https://bitcointalk.org/index.php?topic=51604.0