Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcrp-3q6q-67w2

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

EPSS

Процентиль: 63%
0.00452
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 12 лет назад

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

EPSS

Процентиль: 63%
0.00452
Низкий

Дефекты

CWE-20