Sparkle Updater framework vulnerability

Ask for help and report issues not specific to either the Mac OS X or GTK+ versions of Transmission
Post Reply
Lanark
Posts: 1
Joined: Sat Jan 30, 2016 12:21 pm

Sparkle Updater framework vulnerability

Post by Lanark »

As reported here (https://vulnsec.com/2016/osx-apps-vulnerabilities/) many OSX apps using the sparkle framework are vulnerable to a MITM attack when performing a system update.
The transmission servers already support HTTPS, so I think that all this requires is editing the info.plist to use HTTPS instead of insecure HTTP

Hacker News discussion
https://news.ycombinator.com/item?id=10995802
Post Reply