// For flags

CVE-2011-4447

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.

La característica "encrypt wallet" en wxBitcoin y en bitcoind v0.4.x y anteriores a v0.4.1, y v0.5.0rc no interactúa adecuadamente con la funcionalidad de eliminación de BSDDB, lo cual permite a atacantes dependiendo del contexto obtener claves privadas no encriptadas desde un fichero de monedero Bitcoin mediante el puenteo de la interfaz de BSDDB y a través de la lectura de entradas que han sido marcadas para su borrado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-11-14 CVE Reserved
  • 2012-08-06 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bitcoin
Search vendor "Bitcoin"
Bitcoin Core
Search vendor "Bitcoin" for product "Bitcoin Core"
0.4.0
Search vendor "Bitcoin" for product "Bitcoin Core" and version "0.4.0"
-
Affected
Bitcoin
Search vendor "Bitcoin"
Bitcoin Core
Search vendor "Bitcoin" for product "Bitcoin Core"
0.4.1
Search vendor "Bitcoin" for product "Bitcoin Core" and version "0.4.1"
rc6
Affected
Bitcoin
Search vendor "Bitcoin"
Bitcoin Core
Search vendor "Bitcoin" for product "Bitcoin Core"
0.5.0
Search vendor "Bitcoin" for product "Bitcoin Core" and version "0.5.0"
rc
Affected
Bitcoin
Search vendor "Bitcoin"
Wxbitcoin
Search vendor "Bitcoin" for product "Wxbitcoin"
0.4.0
Search vendor "Bitcoin" for product "Wxbitcoin" and version "0.4.0"
-
Affected
Bitcoin
Search vendor "Bitcoin"
Wxbitcoin
Search vendor "Bitcoin" for product "Wxbitcoin"
0.4.1
Search vendor "Bitcoin" for product "Wxbitcoin" and version "0.4.1"
rc6
Affected
Bitcoin
Search vendor "Bitcoin"
Wxbitcoin
Search vendor "Bitcoin" for product "Wxbitcoin"
0.5.0
Search vendor "Bitcoin" for product "Wxbitcoin" and version "0.5.0"
rc
Affected