CVE-2013-3667: Input Validation
The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3667?
CVE-2013-3667 has been classified as a medium severity vulnerability.
How do I fix CVE-2013-3667?
To fix CVE-2013-3667, update to the latest versions of the affected software, which include Yojimbo 4.0 and later, TextWrangler 4.5.3 and later, and BBEdit 10.5.5 and later.
What software does CVE-2013-3667 affect?
CVE-2013-3667 affects Bare Bones Software Yojimbo, TextWrangler, and BBEdit versions prior to the specified secure releases.
What type of attack is possible due to CVE-2013-3667?
CVE-2013-3667 allows attackers to perform tampering or corruption of software updates.
Is CVE-2013-3667 still a risk if my software is updated?
No, if your software is updated to the fixed versions, CVE-2013-3667 should no longer pose a risk.