CVE-2013-3667
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- barebones/textwrangler · barebones/bbedit · barebones/yojimbo
- Source
- cve@mitre.org
References
- http://www.barebones.com/support/bbedit/arch_bbedit1055.htmlVendor Advisory
- http://www.barebones.com/support/textwrangler/notes_tw453.htmlVendor Advisory
- http://www.barebones.com/support/yojimbo/arch_yojimbo40.htmlVendor Advisory
- https://groups.google.com/forum/#%21msg/bbedit/BjvyUKCM4Gk/ZT_v03QqPqgJ
- http://www.barebones.com/support/bbedit/arch_bbedit1055.htmlVendor Advisory
- http://www.barebones.com/support/textwrangler/notes_tw453.htmlVendor Advisory
- http://www.barebones.com/support/yojimbo/arch_yojimbo40.htmlVendor Advisory
- https://groups.google.com/forum/#%21msg/bbedit/BjvyUKCM4Gk/ZT_v03QqPqgJ
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.