The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2013-12-31T20:00:00

Updated: 2013-12-31T19:57:00

Reserved: 2013-05-24T00:00:00


Link: CVE-2013-3667

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2013-12-31T20:55:15.167

Modified: 2023-11-07T02:16:00.237


Link: CVE-2013-3667

JSON object: View

cve-icon Redhat Information

No data.

CWE