Thanks sanook for raising these concerns and sharing
a solution.
We will be rolling out a patch (3.1.4) shortly to address this. Customers who purchased CP AFTER 4/01/10 (v3.0+) do NOT need TimThumb and can just delete it (/includes/timthumb.php). It was left in there for legacy support.
Everyone else should follow the instructions as mentioned by sanook or wait for the patch to go out.
We'll also be emailing all customers to advise them of this. Thanks.