CVE-2013-2273: Bitcoin Bitcoin-Qt

Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.

bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before 0.7.3rc1 make it easier for remote attackers to obtain potentially sensitive information about returned change by leveraging certain predictability in the outputs of a Bitcoin transaction.

Affected products

  • Bitcoin Bitcoin-Qt: up to and including 0.4.8; version 0.4 only; version 0.5.0 only; version 0.5.0.4 only; version 0.5.1 only; version 0.5.3.0 only; …
  • Bitcoin Bitcoin Core: any version; version 0.3.4 only; version 0.3.5 only; version 0.3.8 only; version 0.3.10 only; version 0.3.11 only; …
  • Bitcoin Bitcoind: up to and including 0.4.4; version 0.5.7 only; version 0.6.0.0 only; version 0.6.0.10 only; version 0.6.3 only; version 0.6.4 only; …

Published 2013-03-12. Last modified 2026-06-16.