« Volver al listado

CVE-2011-4447

Estado: ModificadaMedia (4.3)—

The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4447",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-06T16:55:01.227",
  "references": [
    {
      "url": "http://bitcoin.org/releases/2011/11/21/v0.5.0.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bitcointalk.org/index.php?topic=51474.0",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bitcointalk.org/index.php?topic=51604.0",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://en.bitcoin.it/wiki/CVEs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bitcoin.org/releases/2011/11/21/v0.5.0.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bitcointalk.org/index.php?topic=51474.0",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bitcointalk.org/index.php?topic=51604.0",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://en.bitcoin.it/wiki/CVEs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The \"encrypt wallet\" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion."
    },
    {
      "lang": "es",
      "value": "La característica \"encrypt wallet\" en wxBitcoin y en bitcoind v0.4.x y anteriores a v0.4.1, y v0.5.0rc no interactúa adecuadamente con la funcionalidad de eliminación de BSDDB, lo cual permite a atacantes dependiendo del contexto obtener claves privadas no encriptadas desde un fichero de monedero Bitcoin mediante el puenteo de la interfaz de BSDDB y a través de la lectura de entradas que han sido marcadas para su borrado."
    }
  ],
  "lastModified": "2026-06-16T23:34:54.053",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bitcoin:bitcoin_core:0.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C15FA7C-F87A-45F5-B6A3-5E2DA63AACB6"
            },
            {
              "criteria": "cpe:2.3:a:bitcoin:bitcoin_core:0.4.1:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8494FF99-5D8C-497A-90E7-3D87807F5997"
            },
            {
              "criteria": "cpe:2.3:a:bitcoin:bitcoin_core:0.5.0:rc:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74398A03-74B4-4EC4-A15E-047367614EC7"
            },
            {
              "criteria": "cpe:2.3:a:bitcoin:wxbitcoin:0.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82B766B4-C3FD-42D8-9F7D-767B9C0C20F4"
            },
            {
              "criteria": "cpe:2.3:a:bitcoin:wxbitcoin:0.4.1:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87FCC078-AAF9-4FB4-B46E-EEE5D8488B81"
            },
            {
              "criteria": "cpe:2.3:a:bitcoin:wxbitcoin:0.5.0:rc:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6A8CB89-F0A1-4E97-A053-CACC378BD8C2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}