wxBitcoin and bitcoind contain a flaw that is triggered when the encrypt wallet feature fails to properly communicate with the deletion functionality of BSDDB. This may allow a context-dependent attacker to bypass the BSDDB interface and gain access to potentially sensitive private key information.
Classification
Location:
Context Dependent
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Upgrade to version 0.4.1 or 0.5.0 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.