CVE-2019-8675: Buffer Overflow
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.
Other sources
Apple CUPS is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the libcups's asn1gettype function. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
— IBM
CUPS. A buffer overflow issue was addressed with improved memory handling.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8661
- CVE-2019-8646
- CVE-2019-8660
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8702
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2018-16860
- CVE-2019-8694
- CVE-2019-13118
- CVE-2019-8662
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8675.
What is the severity of CVE-2019-8675?
The severity of CVE-2019-8675 is high.
Which software versions are affected by CVE-2019-8675?
The affected software versions are macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, and Security Update 2019-004 Sierra.
How can an attacker exploit CVE-2019-8675?
An attacker in a privileged network position may be able to execute arbitrary code.
How can I fix CVE-2019-8675?
CVE-2019-8675 is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, and Security Update 2019-004 Sierra.