Software Update Mechanism Vulnerability in Bare Bones Software Products
CVE-2013-3667

Currently unrated

Key Information:

Vendor

Barebones

Vendor
CVE Published:
31 December 2013

What is CVE-2013-3667?

The software update mechanism in Bare Bones Software's Yojimbo, TextWrangler, and BBEdit versions prior to their respective updates fails to adequately download and validate update packages. This oversight allows malicious actors to exploit the process, leading to potential tampering or corruption of the updates. Without proper verification, users are at risk of installing compromised software, which could lead to further security breaches and data integrity issues.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.