SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-3667

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or…

MEDIUM 6.4EPSS 1.81%

Does this matter?

Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.

Description

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
1.81% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
barebones/textwrangler · barebones/bbedit · barebones/yojimbo
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.