CVE-2013-3667 Information
Feb 14, 2021
cve
Description
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0 TextWrangler before 4.5.3 and BBEdit before 10.5.5 does not properly download and verify updates before installation which allows attackers to perform \tampering or corruption\ of the updates.
Reference
http://www.barebones.com/support/bbedit/arch_bbedit1055.html http://www.barebones.com/support/textwrangler/notes_tw453.html http://www.barebones.com/support/yojimbo/arch_yojimbo40.html https://groups.google.com/forum/!msg/bbedit/BjvyUKCM4Gk/ZT_v03QqPqgJ
Share on: