QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
2020-03-05T19:15:11.357
2024-11-21T04:38:20.967
Modified
CVSSv3.1: 3.5 (LOW)
AV:A/AC:L/Au:S/C:N/I:N/A:P
5.1
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qemu | qemu | 4.1.0 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |
Operating System | canonical | ubuntu_linux | 20.04 | Yes |