CVE-2013-3667
N/A
N/A
Summary
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.barebones.com/support/yojimbo/arch_yojimbo40.html
- http://www.barebones.com/support/bbedit/arch_bbedit1055.html
- https://groups.google.com/forum/#%21msg/bbedit/BjvyUKCM4Gk/ZT_v03QqPqgJ
- http://www.barebones.com/support/textwrangler/notes_tw453.html
References
- http://www.barebones.com/support/yojimbo/arch_yojimbo40.html
- http://www.barebones.com/support/bbedit/arch_bbedit1055.html
- https://groups.google.com/forum/#%21msg/bbedit/BjvyUKCM4Gk/ZT_v03QqPqgJ
- http://www.barebones.com/support/textwrangler/notes_tw453.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.