PT-2013-4557 · Bare Bones · Bbedit+2
Chris Hickstein
·
Published
2013-12-31
·
Updated
2018-08-13
·
CVE-2013-3667
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Bare Bones Software Yojimbo versions prior to 4.0
TextWrangler versions prior to 4.5.3
BBEdit versions prior to 10.5.5
Description
The software update mechanism does not properly download and verify updates before installation, allowing attackers to perform tampering or corruption of the updates.
Recommendations
For Bare Bones Software Yojimbo versions prior to 4.0, update to version 4.0 or later.
For TextWrangler versions prior to 4.5.3, update to version 4.5.3 or later.
For BBEdit versions prior to 10.5.5, update to version 10.5.5 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bbedit
Textwrangler
Yojimbo