Vulnerability CVE-2013-3667


Published: 2013-12-31

Description:
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial
Affected software
Barebones -> Bbedit 
Barebones -> Textwrangler 
Barebones -> Yojimbo 

 References:
http://www.barebones.com/support/bbedit/arch_bbedit1055.html
http://www.barebones.com/support/textwrangler/notes_tw453.html
http://www.barebones.com/support/yojimbo/arch_yojimbo40.html
https://groups.google.com/forum/#!msg/bbedit/BjvyUKCM4Gk/ZT_v03QqPqgJ

Copyright 2021, cxsecurity.com

 

Back to Top