First published: Tue Mar 18 2008(Updated: )
The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.5.2 | |
macOS Yosemite | =10.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0995 is classified as a high severity vulnerability due to its potential for enabling brute force attacks on encrypted PDF files.
To mitigate CVE-2008-0995, upgrade to a newer version of macOS that does not use 40-bit RC4 for PDF file encryption.
CVE-2008-0995 affects macOS versions specifically 10.5.2, including both Mac OS X and Mac OS X Server.
CVE-2008-0995 allows attackers to potentially decrypt encrypted PDF files using brute force techniques.
A recommended workaround for CVE-2008-0995 is to avoid using the vulnerable printing feature until a proper update can be applied.