First published: Wed Oct 01 2008(Updated: )
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for attackers to decrypt ciphertext produced by JCE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5.5 | |
Apple iOS and macOS | =10.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-4368 is considered medium due to its implications in cryptography.
To fix CVE-2008-4368, upgrade Java to a version that supports stronger cryptographic policies.
CVE-2008-4368 affects Java 1.5 running on Apple Mac OS X versions 10.5.4 and 10.5.5.
Not addressing CVE-2008-4368 may lead to weakened encryption, making sensitive data more vulnerable to unauthorized access.
CVE-2008-4368 limits JCE key sizes to 128 bits, reducing the cryptographic strength available to applications.