PT-2013-4557 · Bare Bones · Bbedit+2

Chris Hickstein

·

Publicado

2013-12-31

·

Atualizado

2018-08-13

·

CVE-2013-3667

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bare Bones Software Yojimbo versions prior to 4.0 TextWrangler versions prior to 4.5.3 BBEdit versions prior to 10.5.5
Description The software update mechanism does not properly download and verify updates before installation, allowing attackers to perform tampering or corruption of the updates.
Recommendations For Bare Bones Software Yojimbo versions prior to 4.0, update to version 4.0 or later. For TextWrangler versions prior to 4.5.3, update to version 4.5.3 or later. For BBEdit versions prior to 10.5.5, update to version 10.5.5 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3667

Produtos afetados

Bbedit
Textwrangler
Yojimbo