Apple · Macos Mojave · CVE-2019-8696
**Name of the Vulnerable Software and Affected Versions**
CUPS versions prior to the version included in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
**Description**
The issue is caused by a buffer overflow in the `asn1 get packed` function of the libcups library in the CUPS print server. This can be exploited by a remote attacker to cause a denial of service. An attacker in a privileged network position may be able to execute arbitrary code due to a buffer overflow issue, which has been addressed with improved memory handling.
**Recommendations**
For versions prior to the fixed version, consider applying the Security Update 2019-004 to High Sierra or Sierra, or updating to macOS Mojave 10.14.6 to resolve the issue.
As a temporary workaround, consider restricting access to the CUPS print server to minimize the risk of exploitation.